The Exploit Bulletin

Archives
Log in
Subscribe
September 12, 2026

The Exploit Bulletin — Saturday, September 12, 2026: 1 issue requires action

Saturday, September 12, 2026 — 1 issue requires action. If you run none of the software below, you are done.

Affects: GitLab CE/EE


1. Unauthenticated arbitrary file read via path traversal in GitLab repository commits API (CVE-2026-85706)

CISA KEV (due 2026-09-14) · DATA EXPOSURE · CRITICAL · CVSS 10.0

CISA added this CVSS 10.0 flaw to KEV on 2026-09-11 after watchTowr observed in-the-wild exploitation attempts one day after GitLab's patch release, so unpatched internet-facing GitLab servers are being actively hunted right now and any team that waits risks having server secrets and repository contents read out.

A path traversal combined with missing authentication enforcement in the GitLab CE/EE repository commits API lets an unauthenticated remote attacker read arbitrary files from the GitLab server in a single HTTP request. Files readable this way can include server configuration and secrets, giving an attacker a path to full compromise of the instance and the code it hosts.

Affected: GitLab CE/EE >= 18.7 < 19.1.8; GitLab CE/EE >= 19.2 < 19.2.6; GitLab CE/EE >= 19.3 < 19.3.2

How to Test: Confirm the running GitLab version (Admin Area or the /help page) and treat anything from 18.7 up to but below 19.1.8, 19.2.6, or 19.3.2 as vulnerable. Review web/API access logs for unauthenticated requests to the repository commits API endpoints containing path traversal sequences (e.g. '../' or encoded variants) and for responses that returned file contents outside the repository; if found, assume secrets on the server were exposed and rotate them.

How to Patch: Upgrade to GitLab 19.1.8, 19.2.6, or 19.3.2 (or later) for the respective release line. If the upgrade must wait, restrict network access to the GitLab instance so the API is not reachable from the internet until patched.

Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · SecurityWeek: watchTowr observed in-the-wild exploitation attempts one day after disclosure · BleepingComputer: attackers scanning for unpatched GitLab servers · The Hacker News: in-the-wild probes within hours of disclosure

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
Older → The Exploit Bulletin — Friday, September 11, 2026: 1 issue requires action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.