Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Rapid7 Version 1 original

Imported from official source

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. …

This version

Version
1 of 2
Recorded
September 18, 2026 11:35
Change
Initial
Content hash
f20e938ee2e80152b8a9c2875acf1b27
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.