Download Privacy Needle App

Type to search

Cybersecurity

GitLab Users Urged to Patch Critical Path Traversal Flaw Under Active Exploitation

Share

GitLab users are being urged to patch a critical path traversal vulnerability that is currently being exploited in the wild. The flaw, tracked as CVE-2026-85706, has been assigned a maximum CVSS severity score of 10.0.

The vulnerability allows unauthenticated users to read arbitrary files from a GitLab server. This is possible due to improper path confinement and missing authentication enforcement within the repository commits API.

Active Exploitation Detected

Cybersecurity vendor Watchtower reported detecting “in-the-wild probes” for the bug on 11 September. While GitLab has not officially flagged the vulnerability as being exploited, the detection of active probing suggests that widespread exploitation may be imminent.

The US Cybersecurity and Infrastructure Security Agency (CISA) has also added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. Civilian federal agencies are mandated to remediate the issue by 15 September, although CISA recommends that private sector organisations follow similar patching protocols.

Affected Versions and Remediation

The vulnerability affects GitLab CE and EE in the following versions:

  • All versions of 18.7 prior to 19.1.8
  • All versions of 19.2 prior to 19.2.6
  • All versions of 19.3 prior to 19.3.2

Organisations running self-hosted GitLab instances that are accessible via the public internet should patch immediately or remove public access to mitigate the risk. Security teams can identify potential exploitation attempts by searching log files for HTTP POST requests to the /api/v4/projects/{id}/repository/commits/ URI containing “file.path” parameters.

The emergence of this flaw comes amid warnings from security experts that AI tools are being used by threat actors to identify novel vulnerabilities and weaponise them more rapidly than in previous years.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.