CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Rapid7 Version 2 imported change current

Imported from official source

On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. …

This version

Version
2 of 2
Recorded
September 24, 2026 17:00
Change
Imported change
Content hash
fba9d3d63e31f964f10fd48966ebd8de
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.