LmCast :: Stay tuned in

GitLab urges users to patch max severity path traversal flaw

Recorded: Sept. 11, 2026, 12:10 p.m.

Original Summarized

GitLab urges users to patch max severity path traversal flaw

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

GitLab urges users to patch max severity path traversal flaw

Learn to use Claude beyond basic prompts with this $20 course bundle

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityGitLab urges users to patch max severity path traversal flaw

GitLab urges users to patch max severity path traversal flaw

By Sergiu Gatlan

September 11, 2026
07:15 AM
0

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
The security flaw, discovered by a security researcher using the 's3ntago' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API.
According to GitLab, unauthenticated attackers can exploit CVE-2026-85706 to read arbitrary files from vulnerable servers "under certain conditions."
Yesterday, GitLab patched a second critical vulnerability tracked as CVE-2026-87719 that stems from an insecure deserialization weakness in the GraphQL subscription serializer.
CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
"These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately," the company warned on Thursday. "GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action."
In May 2023, GitLab addressed another maximum severity path traversal flaw (CVE-2023-2825) that exposes sensitive data, including proprietary software code, user credentials, tokens, and files on unpatched servers.
One year later, CISA and the FBI urged software companies to weed out path traversal security vulnerabilities from their products before shipping, saying that such flaws "have been called 'unforgivable' since at least 2007."
More recently, in January, GitLab also patched a high-severity two-factor authentication bypass affecting community and enterprise editions that enables attackers who know the target's account ID to circumvent two-factor authentication.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged four GitLab vulnerabilities as exploited in attacks, including two (CVE-2021-22175 and CVE-2021-39935) in February this year.
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Over 36,000 exposed Plex servers vulnerable to recent flawsPlex warns users to patch security vulnerabilities immediatelyCISA orders urgent patching of actively exploited Zimbra flawCitrix urges admins to patch new NetScaler flaws as soon as possibleProgress confirms ShareFile zero-day flaw behind Storage Zone shutdown

GitLab
Path Traversal
Vulnerability
Warning

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

September Windows Server updates break Remote Desktop Services

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

GitLab recently urged its users to immediately patch critical security vulnerabilities, highlighting issues related to path traversal flaws and insecure deserialization within their platform. A maximum-severity path traversal vulnerability, tracked as CVE-2026-85706, was discovered by a security researcher and originated from improper path confinement and a lack of authentication enforcement within the repository commits API. This flaw allowed unauthenticated attackers under specific conditions to read arbitrary files from vulnerable servers. Additionally, GitLab patched another critical vulnerability, CVE-2026-87719, which involves an insecure deserialization weakness in the GraphQL subscription serializer. This second issue specifically affected GitLab Enterprise Edition and permitted authenticated users possessing Duo Chat access to exfiltrate sensitive credentials and Advanced Search instance configurations.

GitLab addressed these security concerns by releasing updates in versions 19.3.2, 19.2.6, and 19.1 on Thursday, strongly recommending that all self-managed GitLab installations be upgraded immediately. The company noted that GitLab.com was already running the patched version, while GitLab Dedicated customers were not required to take action. Furthermore, the advisory references a history of similar issues, noting that in May 2023, GitLab had addressed a maximum severity path traversal flaw, CVE-2023-2825, which exposed sensitive assets such as proprietary software code, user credentials, tokens, and files on unpatched servers. Earlier, in January, GitLab had also patched a high-severity vulnerability concerning two-factor authentication bypasses that could allow attackers to circumvent two-factor authentication by knowing a target's account ID. The organization's DevSecOps platform is utilized by numerous large entities, including Nvidia, Lockheed Martin, and Goldman Sachs, underscoring the importance of these security maintainances. These developments are situated within a broader context where the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have previously advised software companies to eliminate path traversal vulnerabilities before product shipment, deeming such flaws unacceptable.