Home / Sep 12, 2026 / Story
0
#1 The Hacker News general September 11, 2026 at 16:30 UTC

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

By [email protected] (The Hacker News)

AI Summary

CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab's repository commits API, allows unauthenticated attackers to read arbitrary files from self-managed GitLab servers. Internet-wide probing began within hours of public disclosure, making this an urgent patch priority for any organization running self-hosted GitLab instances.

Relevance score: 88.0/100

# More from September 12