GitLab urges users to patch max severity path traversal flaw
Recorded: Sept. 11, 2026, 12:10 p.m.
| Original | Summarized |
GitLab urges users to patch max severity path traversal flaw News Featured AdaptHealth confirms 4.1 million people exposed in July cyberattack Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Over 36,000 exposed Plex servers vulnerable to recent flaws New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access GitLab urges users to patch max severity path traversal flaw Learn to use Claude beyond basic prompts with this $20 course bundle Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs Trezor: 347,000 users targeted in phishing attacks after Brevo breach Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityGitLab urges users to patch max severity path traversal flaw GitLab urges users to patch max severity path traversal flaw By Sergiu Gatlan September 11, 2026 GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: GitLab Sergiu Gatlan Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days September Windows Server updates break Remote Desktop Services New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Sponsor Posts Overdue a password health-check? Audit your Active Directory for free EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
GitLab recently urged its users to immediately patch critical security vulnerabilities, highlighting issues related to path traversal flaws and insecure deserialization within their platform. A maximum-severity path traversal vulnerability, tracked as CVE-2026-85706, was discovered by a security researcher and originated from improper path confinement and a lack of authentication enforcement within the repository commits API. This flaw allowed unauthenticated attackers under specific conditions to read arbitrary files from vulnerable servers. Additionally, GitLab patched another critical vulnerability, CVE-2026-87719, which involves an insecure deserialization weakness in the GraphQL subscription serializer. This second issue specifically affected GitLab Enterprise Edition and permitted authenticated users possessing Duo Chat access to exfiltrate sensitive credentials and Advanced Search instance configurations. GitLab addressed these security concerns by releasing updates in versions 19.3.2, 19.2.6, and 19.1 on Thursday, strongly recommending that all self-managed GitLab installations be upgraded immediately. The company noted that GitLab.com was already running the patched version, while GitLab Dedicated customers were not required to take action. Furthermore, the advisory references a history of similar issues, noting that in May 2023, GitLab had addressed a maximum severity path traversal flaw, CVE-2023-2825, which exposed sensitive assets such as proprietary software code, user credentials, tokens, and files on unpatched servers. Earlier, in January, GitLab had also patched a high-severity vulnerability concerning two-factor authentication bypasses that could allow attackers to circumvent two-factor authentication by knowing a target's account ID. The organization's DevSecOps platform is utilized by numerous large entities, including Nvidia, Lockheed Martin, and Goldman Sachs, underscoring the importance of these security maintainances. These developments are situated within a broader context where the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have previously advised software companies to eliminate path traversal vulnerabilities before product shipment, deeming such flaws unacceptable. |