Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Published: 2026-09-12
Score: 10 Critical
EPSS: 93.0% High
KEV: Yes
Impact: Remote File Disclosure
Action: Immediate Patch
AI Analysis

Impact

GitLab has a path traversal flaw in its repository commits API that, under certain conditions, allows an unauthenticated user to read arbitrary files from the server. The flaw arises from improper pathname limitation and the lack of authentication enforcement, enabling attackers to construct file paths that escape the intended restricted directory and access any file on the GitLab instance. This omission permits the disclosure of sensitive data such as configuration files, credentials, or codebases without requiring credentials.

Affected Systems

The vulnerability affects GitLab Community Edition and Enterprise Edition from version 18.7 up through all intermediate 18.x releases, through 19.0 before 19.0.9, and extends to 19.1.x before 19.1.8, 19.2.x before 19.2.6 and 19.3.x before 19.3.2. Any GitLab installation running a version in these ranges is susceptible.

Risk and Exploitability

The CVSS score of 10 reflects the severity of this data exposure and the high impact on confidentiality. An EPSS score of 93% indicates that the vulnerability is highly likely to be exploited in the wild. It is catalogued in the CISA KEV list, underscoring its known exploitation risk. Attackers would target the public repository commits API endpoint, sending specially crafted requests that bypass directory restrictions to retrieve arbitrary files. No authentication is required, so the attack vector is broad and generally low in technical barrier.

Generated by OpenCVE AI on October 1, 2026 at 20:44 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to a patched release, 18.11.12 or later, 19.0.9 or later, 19.1.8 or later, 19.2.6 or later, 19.3.2 or later.
  • Limit access to the repository commits API by firewalling or applying appropriate network access controls.
  • Continuously monitor GitLab logs for anomalous file read attempts or unexpected API usage patterns.

Generated by OpenCVE AI on October 1, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 11:30:00 +0000


Sat, 12 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Title Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-22
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}

kev

{'dateAdded': '2026-09-11T00:00:00+00:00', 'dueDate': '2026-09-14T00:00:00+00:00'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-23T21:03:18.163Z

Reserved: 2026-09-04T14:34:20.856Z

Link: CVE-2026-85706

cve-icon Vulnrichment

Updated: 2026-09-12T10:53:26.759Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-12T03:16:30.473

Modified: 2026-09-24T12:52:28.143

Link: CVE-2026-85706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:45:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')