#1
The Hacker News
general
September 11, 2026 at 16:30 UTC
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
By [email protected] (The Hacker News)
AI Summary
CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab's repository commits API, allows unauthenticated attackers to read arbitrary files from self-managed GitLab servers. Internet-wide probing began within hours of public disclosure, making this an urgent patch priority for any organization running self-hosted GitLab instances.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →