TTO-2026-0912-121 · September 12, 2026 Active ExploitationCritical

GitLab CVE-2026-85706 CVSS 10.0 Draws Internet-Wide Probes Within Hours — CISA Deadline September 14

gitlab.comCVE-2026-85706 CVSS 10.0Unauthenticated file readCISA KEV Sep 14 deadlinePoC publicWatchTowr honeypot confirmed probes

Summary

GitLab released patches on September 11, 2026 for CVE-2026-85706, a maximum-severity path traversal vulnerability in the GitLab Community Edition and Enterprise Edition repository commits API that allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server. CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11 and set a federal agency remediation deadline of September 14, 2026 — the shortest possible window under Binding Operational Directive 26-04. WatchTowr Labs reported active internet-wide probes against its honeypot network within hours of public disclosure. A public proof-of-concept exploit was available by September 12.

Timeline

DateEvent
Sep 11, 2026GitLab releases patched versions 19.1.8, 19.2.6, and 19.3.2; vulnerability reported by s3ntago via HackerOne bug bounty
Sep 11, 2026WatchTowr Labs detects active probes against CVE-2026-85706 as of 6:00 UTC — within hours of public disclosure
Sep 11, 2026CISA adds CVE-2026-85706 to KEV catalog; sets Sep 14 federal remediation deadline; marks for forensic triage under BOD 26-04
Sep 12, 2026Public PoC exploit published; WatchTowr independently validates exposure of self-managed GitLab instances

What Happened

CVE-2026-85706 is a path traversal flaw in GitLab's repository commits API caused by improper path confinement and missing authentication enforcement. An unauthenticated attacker can supply crafted path values that escape the intended repository directory structure and request arbitrary files from the server filesystem. The only precondition is that one public project exists on the targeted instance — a condition met by most internet-facing GitLab deployments.

Depending on the GitLab deployment configuration and service permissions, accessible files could include application configuration files containing secrets, API credentials, deployment tokens, private keys, environment variables, CI/CD pipeline configuration, repository metadata, and log files containing authentication artifacts. An attacker who reads these materials could pivot to account compromise, source-code theft, cloud environment access, or lateral movement into connected infrastructure.

The vulnerability affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. Organizations should upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately and rotate any credentials that may have been accessible from the server filesystem. CISA has instructed that forensic triage be performed on vulnerable systems under BOD 26-04, reflecting the possibility that systems may have been accessed before patching. A second GitLab vulnerability, CVE-2026-87719, which may expose Enterprise Edition settings and passwords, was also added to the CISA KEV catalog on September 11.

Domain Intelligence

gitlab.com — 73.27

gitlab.com scores at 73.27, in the high-trust range, with a single unconfirmed threat intelligence source flag that does not reduce the published score under WarmBadge's methodology. GitLab is the vendor that identified and patched CVE-2026-85706. The score reflects gitlab.com's domain trust posture and is not a measure of the severity of the vulnerability in its product, which at CVSS 10.0 is the maximum possible.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 12, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026