GitLab Faces Critical Security Threat as Hackers Exploit Maximum Severity Flaw

Businesses urged to act quickly as a path traversal vulnerability puts sensitive files on vulnerable servers at risk

Washington, D.C., 15 September 2026 – A critical security flaw in GitLab is drawing urgent attention after cybersecurity researchers detected exploitation attempts against vulnerable systems. The U.S. Cybersecurity and Infrastructure Security Agency has added the vulnerability, tracked as CVE 2026 85706, to its Known Exploited Vulnerabilities catalog, highlighting the need for organizations to address the issue quickly.

The vulnerability has received a CVSS score of 10 out of 10, the highest possible severity rating. It affects GitLab Community Edition and Enterprise Edition installations and is linked to the repository commits API. Under certain conditions, an attacker who does not have an account can exploit the flaw to read arbitrary files from a vulnerable GitLab server.

The problem is caused by two security weaknesses. The first involves improper path confinement, which means the system may not properly restrict access to files within an intended directory. The second involves missing authentication enforcement in the affected API. Together, these issues can allow unauthorized users to access sensitive information.

For businesses, the potential impact is significant. GitLab is widely used to manage source code, software development projects, credentials, configuration information, and other important data. If an attacker gains access to sensitive files, the information could potentially be used to support further attacks or compromise other parts of an organization’s technology environment.

Security researchers at watchTowr reported seeing probes targeting the vulnerability shortly after GitLab released its security fixes. The activity suggests that attackers are actively searching for systems that have not yet been updated. Researchers have warned that widespread exploitation could develop quickly as more details about the vulnerability become available.

GitLab addressed the vulnerability with updates released on September 10. The affected versions were addressed in GitLab 19.1.8, 19.2.6, and 19.3.2. Organizations operating self managed GitLab installations are being encouraged to upgrade to the appropriate fixed version as soon as possible. GitLab.com is already running a patched version, while GitLab Dedicated customers do not need to take action for this particular issue.

CISA’s addition of the vulnerability to its Known Exploited Vulnerabilities catalog adds another level of urgency. Federal civilian agencies are required to follow specific remediation timelines for vulnerabilities listed in the catalog. However, the warning is also relevant to private businesses because the catalog is widely used as a resource for prioritizing vulnerabilities that are already being exploited.

Organizations should also review their security logs for signs of suspicious activity. Researchers have recommended looking for unusual requests involving GitLab’s repository commits API, particularly requests containing file path parameters. This can help security teams determine whether an exposed installation may have been targeted.

The incident also highlights a wider challenge for modern software teams. Development platforms often contain valuable information that extends beyond source code. Credentials, access tokens, configuration files, deployment information, and other secrets can make these systems attractive targets for cybercriminals.

For organizations using self hosted GitLab, the message is straightforward. Updating vulnerable systems is the most important immediate step, followed by checking logs and reviewing exposed services. Where an update cannot be applied immediately, organizations should consider reducing public exposure while assessing the risk.

The GitLab vulnerability is another reminder that security teams must respond quickly when critical flaws move from disclosure to active exploitation. In an environment where development infrastructure is closely connected to business operations, keeping software platforms updated is an essential part of protecting the wider digital environment.

Previous article

Hot Topics

Related Articles