Sploitus Arbitrary File Reading Vulnerability in GitLab (CVE-2026-85706)
Article Content
- •CVE-2026-85706 allows unauthorized file access in GitLab CE/EE.
- •Affected versions include 18.7 and later; patches were released on September 10, 2026.
- •Proof-of-concept code is available, indicating active exploitation potential.
GitLab's Workhorse component has a vulnerability (CVE-2026-85706) allowing unauthenticated attackers to read arbitrary files. This issue affects GitLab CE/EE versions 18.7 and later. Attackers can exploit this by manipulating request parameters, bypassing security filters. The vulnerability was publicly disclosed on September 12, 2026, and added to CISA's KEV list on September 11, 2026. Proof-of-concept code is available, enabling exploitation without authentication. The vulnerability allows access to sensitive files like '/etc/passwd'. GitLab has released patches for affected versions on September 10, 2026. Users are urged to update immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-85706 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…