Maximum Severity GitLab Flaw Puts Supply Chains at Risk
Recorded: Sept. 14, 2026, 9:08 p.m.
| Original | Summarized |
Maximum Severity GitLab Flaw Puts Supply Chains at Risk Informa TechTarget|SearchSecurityCybersecurity DiveInformationWeekChannel DiveExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsSponsored ContentThe Mythos Panic Is Over. The Budget Window Isn't.The Mythos Panic Is Over. The Budget Window Isn't.Sep 14, 20265 Min ReadMobile SecurityIndonesia Hit by Android Banking App-Cloning CampaignIndonesia Hit by Android Banking App-Cloning CampaignbyAlexander CulafiSep 11, 20264 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryCyberattacks & Data BreachesApplication SecurityVulnerabilities & ThreatsCyber RiskNewsMaximum Severity GitLab Flaw Puts Supply Chains at RiskCVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.Rob Wright,Senior News Director,Dark ReadingSeptember 14, 20263 Min ReadSource: Infinite Creations via Getty ImagesThreat actors are exploiting a maximum-severity GitLab vulnerability disclosed last week, which could give adversaries an inside track into organizations' software supply chains.CVE-2026-85706, which GitLab disclosed and patched on Sept. 10, is a path traversal flaw that allows unauthenticated individuals to read arbitrary files from the GitLab server. The vulnerability, which received a CVSS score of 10 out of 10, stems from improper path confinement and missing authentication checks in the platform's repository commits API, according to GitLab's advisory. The vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE), which organizations use to set up self-hosted GitLab instances within their environments.The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on Friday and required federal agencies to patch or disable their self-managed GitLab instances by today. On the same day, researchers with cybersecurity vendor watchTowr observed behavioral probes for the flaw on its honeypot network.Related:Threat Actor Generates 1M Personalized Fraud Emails in 3 DaysAnd it's gotten worse since then.GitLab Exploitation Jeopardizes Supply ChainsJake Knott, head of threat intelligence at watchTowr, tells Dark Reading that malicious activity quickly escalated on Friday to full exploitation and the exfiltration of sensitive files."Over the weekend, we also observed threat actors dumping config files for secrets along with system SSH configurations for the victim system," Knott says. "The combination is, as you can imagine, potent, as it may allow threat actors the ability to extract passwords, connect to instances that allow password authentication, and gain access to the host under the right conditions."Even though CVE-2026-85706 exploitation gives an attacker read-only access to a GitLab instance, the attacker could use that access to obtain sensitive information like credentials and CI/CD secrets; this could not only enable a full compromise of the GitLab instance but also grant the attacker further admission into an organization's development environment and other critical downstream systems. Knott describes the flaw as a supply chain attack-enabling vulnerability.WatchTowr noted that CVE-2026-85706 is the second critical vulnerability in GitLab to be targeted recently. Last month, attackers exploited CVE-2026-19478, a GraphQL code injection flaw, shortly after it was publicly disclosed.Mitigating CVE-2026-85706On the bright side, Knott says exploitation of CVE-2026-85706 requires the targeted organization to have at least one public project on the GitLab server. On the not-so-bright side, it's "probably a relatively common configuration," and some organizations might not be aware that they have public projects on the platform, he says.Related:Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain"Organizations running GitLab may gate access to the system, meaning projects would not be visible to an outsider without authentication, but that does not mean that projects that were created as 'public' are out of reach," Knott says. "In some cases, companies might want specific codebases to be exposed publicly. In others, they might falsely assume that the project is still 'internal' if it's made public within their GitLab system."WatchTowr urged GitLab customers to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for GitLab Community Edition and Enterprise Edition. If they cannot update, they should immediately remove all public access to their instances. GitLab Dedicated customers do not need to take action, according to GitLab. The online GitLab.com platform has already patched the flaw.Additionally, watchTowr recommended that security teams review access logs on the repository commits API for any suspicious or unauthenticated requests that suggest probing or exploitation activity.Related:Attackers Use Multi-Hop Google Redirects for Phishing CampaignAbout the AuthorRob WrightSenior News Director, Dark ReadingRob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends.Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding.At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area.See more from Rob WrightWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsCybersecurity Outlook 2027Threat Exposure Analytics: Measuring and Communicating Security RiskBenchmark Scores Are a False FlagBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyberattacks & Data BreachesOpenAI Agents Took Over Wiki Site Before Hugging Face AttackOpenAI Agents Took Over Wiki Site Before Hugging Face AttackbyNate NelsonSep 8, 20267 Min ReadApplication SecurityMythos Vulnerability Firehose Hits a Human BottleneckMythos Vulnerability Firehose Hits a Human BottleneckbyJai VijayanSep 9, 20264 Min ReadWant more Dark Reading stories in your Google search results?How Organizations Are Managing Incident ResponseNearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report.Download NowNovember 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
Threat actors are currently exploiting a maximum severity vulnerability in GitLab, identified as CVE-2026-85706, which presents a significant risk to software supply chains. This flaw is a path traversal vulnerability carrying a perfect score of ten out of ten on the Common Vulnerability Scoring System severity scale. It affects both GitLab Community Edition and Enterprise Edition instances, stemming from improper path confinement and insufficient authentication checks within the platform's repository commits API. This vulnerability permits unauthenticated individuals to read arbitrary files directly from the GitLab server. The exploitation of this vulnerability carries profound implications for organizational security. As noted by Jake Knott, head of threat intelligence at watchTowr, successful exploitation allows attackers to gain read-only access to the GitLab instance, which can be leveraged to extract highly sensitive information, including credentials, CI/CD secrets, and system SSH configurations. This combination of data can grant threat actors access to sensitive passwords, host instances allowing password authentication, and overall control over the host environment under certain conditions. Consequently, the flaw is described as a vulnerability that enables a supply chain attack. The potential impact extends beyond the GitLab instance itself, allowing adversaries to potentially gain admission into an organization's entire development environment and other critical downstream systems by compromising these source repositories. Researchers at watchTowr observed behavioral probes targeting this flaw on their network, indicating active exploitation. Furthermore, this vulnerability is notable because it represents the second critical vulnerability recently targeted against GitLab, following the exploitation of CVE-2026-19478, a GraphQL code injection flaw, in the previous month. Mitigating the risk associated with CVE-2026-85706 requires specific actions from affected organizations. Knott emphasized that exploitation is more likely if the GitLab server hosts at least one public project, suggesting that many organizations may be unaware of their public project exposure. To mitigate the risk, watchTowr recommended that GitLab customers prioritize updating their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for both Community Edition and Enterprise Edition. If immediate updates are not feasible, organizations must remove all public access to their instances. Additionally, security teams are advised to thoroughly review access logs pertaining to the repository commits API for any suspicious or unauthenticated requests that signal probing or exploitation activity. While GitLab Dedicated customers are noted not to require these specific updates, the online GitLab.com platform has already been patched. |