A maximum-severity vulnerability, CVE-2026-85706 with a CVSS score of 10.0, allows attackers to read arbitrary files in a single HTTP request due to improper confinement and lack of authentication enforcement in GitLab's repository commits API. This flaw impacts GitLab Community Edition (CE) and Enterprise Edition (EE), versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, potentially leading to unauthorized access to configuration files, secrets, or credentials on the GitLab server. The consequences of this vulnerability could extend beyond the affected instance, resulting in credential theft, lateral movement, source code exposure, and supply chain compromise. As a result, organizations should patch immediately, hunt for suspicious repository-commits API activity, and investigate whether exposed files contained credentials or secrets that may now require rotation. Enterprises should also consider identifying exploitation attempts by hunting through log files for HTTP POST requests to specific URIs containing file path parameters.
We recommend you to update GitLab to version 18.7.[/subscribe_to_unlock_form]
A maximum-severity vulnerability, CVE-2026-85706 with a CVSS score of 10.0, allows attackers to read arbitrary files in a single HTTP request due to improper confinement and lack of authentication enforcement in GitLab's repository commits API. This flaw impacts GitLab Community Edition (CE) and Enterprise Edition (EE), versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, potentially leading to unauthorized access to configuration files, secrets, or credentials on the GitLab server. The consequences of this vulnerability could extend beyond the affected instance, resulting in credential theft, lateral movement, source code exposure, and supply chain compromise. As a result, organizations should patch immediately, hunt for suspicious repository-commits API activity, and investigate whether exposed files contained credentials or secrets that may now require rotation. Enterprises should also consider identifying exploitation attempts by hunting through log files for HTTP POST requests to specific URIs containing file path parameters.
We recommend you to update GitLab to version 18.7.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]