TechNewsReel
Live

CISA Warns of Actively Exploited CVSS 10.0 GitLab Vulnerability

A critical path traversal flaw allows unauthenticated attackers to read arbitrary files from affected GitLab servers.

TechNewsReel Newsroom · September 14, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning after a critical vulnerability in GitLab was found to be actively exploited in the wild. The flaw, tracked as CVE-2026-85706, allows remote attackers to bypass security controls and access sensitive system files without any prior authentication.

On September 11, 2026, CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling that the flaw is being used in real-world attacks. The vulnerability is a path traversal flaw (CWE-35) located within the repository commits API. This specific weakness enables unauthenticated users to perform arbitrary file reads from the affected servers. Due to the severity of the risk, CISA has mandated that federal civilian executive branch agencies remediate the flaw by September 14, 2026.

The Scope of Exposure

The vulnerability carries a maximum CVSS severity score of 10.0, the highest possible rating, reflecting the ease of exploitation and the potential for total system compromise. According to security reports, the flaw affects several versions of GitLab Community Edition (CE) and Enterprise Edition (EE), specifically versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1.

As a DevSecOps platform, GitLab is central to the software development lifecycle, managing source control and CI/CD pipelines. Because these servers typically host proprietary source code, deployment scripts, and sensitive access tokens, they are primary targets for attackers aiming to compromise software supply chains. The exposure is particularly serious because it requires no account, user interaction, or prior access, which substantially lowers the barrier for internet-based exploitation.

Industry Implications

The ability to read arbitrary files on a GitLab server provides a direct path for attackers to steal credentials and configuration data. Once this information is exfiltrated, threat actors can pivot deeper into an organization's internal infrastructure or steal high-value intellectual property. In an era of increasing supply chain attacks, a vulnerability that grants unauthenticated access to the heart of the development environment represents a systemic risk to any organization utilizing the affected versions.

Next Steps for Administrators

Organizations running the affected versions of GitLab CE or EE must prioritize immediate patching to close the traversal gap in the repository commits API. Security teams are advised to audit their GitLab logs for unusual requests to the commits API that may indicate attempted or successful exploitation. While CISA has set a strict deadline for federal agencies, private sector entities are urged to follow suit to prevent the theft of sensitive credentials and source code.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.