Download Privacy Needle App

Type to search

Cybersecurity

Active Exploitation of Critical GitLab Flaw Risks Software Supply Chains

Share

Threat actors are actively exploiting a maximum-severity vulnerability in GitLab that could allow attackers to infiltrate software supply chains.

The flaw, identified as CVE-2026-85706, is a path traversal vulnerability with a CVSS score of 10 out of 10. It enables unauthenticated individuals to read arbitrary files from a GitLab server by exploiting improper path confinement and missing authentication checks within the platform’s repository commits API.

Supply Chain and Credential Risks

While the vulnerability provides read-only access, the practical consequences are severe. Researchers at the cybersecurity firm watchTowr have reported seeing threat actors move beyond simple probing to full exploitation. This includes the exfiltration of sensitive files, such as configuration files containing secrets and system SSH configurations.

Jake Knott, head of threat intelligence at watchTowr, noted that obtaining these credentials could allow attackers to gain access to the host system and move laterally into an organisation’s development environment and other critical downstream systems.

CISA Mandates Patching

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalogue. Following this designation, federal agencies have been required to patch or disable their self-managed GitLab instances.

The vulnerability specifically affects GitLab Community Edition (CE) and Enterprise Edition (EE) instances that are self-hosted. The risk is concentrated on instances that have at least one public project. Even if an organisation attempts to gate access to the system, projects explicitly marked as ‘public’ remain vulnerable to unauthenticated access.

Mitigation and Patching Guidance

GitLab has released patches to address the issue. Organisations running self-hosted instances should immediately update to one of the following versions:

  • 19.3.2
  • 19.2.6
  • 19.1.8

For those unable to apply updates immediately, the recommended mitigation is to remove all public access to the GitLab instance. GitLab has confirmed that customers using the hosted GitLab.com platform or GitLab Dedicated are not affected by this flaw.

Security teams are also advised to review access logs for the repository commits API to identify any unauthenticated requests that may indicate probing or exploitation attempts.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.