Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Was Trump rescued by 2 firefighters after 9/11?

    September 11, 2026

    Flavio Bolsonaro probed for corruption as Brazil election tightens

    September 11, 2026

    Sweden’s NATO missions are at risk if the left wins election, warns PM Kristersson – POLITICO

    September 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Was Trump rescued by 2 firefighters after 9/11?
    • Flavio Bolsonaro probed for corruption as Brazil election tightens
    • Sweden’s NATO missions are at risk if the left wins election, warns PM Kristersson – POLITICO
    • An extraordinary result – why did MPs reject assisted dying bill this time?
    • UK lawmakers urge Burnham to back ban on superintelligent AI after chilling warnings | AI (artificial intelligence)
    • Matt Mullenweg reportedly returns as Automattic CEO two days after getting booted
    • GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
    • Bitwise to Close Dogecoin ETF Before Its First Anniversary
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 11, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 11, 2026Vulnerability / Web Security

    GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.

    The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under certain conditions.

    The problem, per GitLab, stems from “improper path confinement and missing authentication enforcement in the repository commits API.”

    The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) –

    • All versions from 18.7 before 19.1.8,
    • All versions from 19.2 before 19.2.6, and
    • All versions from 19.3 before 19.3.2

    According to preemptive exposure management firm watchTowr, the vulnerability is already witnessing active in-the-wild probes since 06:00 UTC on September 11, 2026. The issue, it said, allows an external attacker to read log files and GitLab-specific configuration files to obtain credentials, secrets, and sensitive information.

    Cybersecurity

    “This is the second instance of a critical severity GitLab vulnerability in recent weeks, following the previous GraphQL code injection (CVE-2026-19478) that was almost immediately actively exploited,” Jake Knott, head of threat intelligence at watchTowr, said in a statement shared with The Hacker News. “Exploitation requires just one requirement, at least one public project must exist.”

    “The appeal to attackers of GitLab is obvious, as unauthorized access allows an attacker to gain access to source code, CI/CD secrets, credentials, and the ability to inject code into build pipelines, gaining access or poisoning anything downstream of it, which as we’ve seen throughout this year has been a favorite of attackers.”

    Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.

    The vulnerability could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup,” GitLab said.

    Organizations running self-managed GitLab instances that are exposed to the internet must apply the patches as soon as possible, or limit public access, if not required.

    “Based on the history, the transition of this vulnerability to indiscriminate mass exploitation is likely not far away, and defenders have limited time to act,” Knott said. “Where possible, organizations should also review log files for HTTP POST requests to ‘/api/v4/projects/{id}/repository/commits/’ URIs containing ‘file.Path’ parameters to identify potential exploitation attempts.”

    CVSS Disclosure draws FileRead Flaw GitLab IntheWild probes
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    How AI and cybersecurity are reshaping ServiceNow

    How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

    Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

    Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Was Trump rescued by 2 firefighters after 9/11?

    September 11, 2026

    Flavio Bolsonaro probed for corruption as Brazil election tightens

    September 11, 2026

    Sweden’s NATO missions are at risk if the left wins election, warns PM Kristersson – POLITICO

    September 11, 2026

    An extraordinary result – why did MPs reject assisted dying bill this time?

    September 11, 2026
    Latest Posts

    After 3 reverse stock splits and a $13.5M loss, this real estate firm bet $8M on crypto it may not be allowed to withdraw

    August 3, 2026

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026

    Europe’s ETS revision is an opportunity to strengthen maritime competitiveness – POLITICO

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Was Trump rescued by 2 firefighters after 9/11?

    September 11, 2026

    Flavio Bolsonaro probed for corruption as Brazil election tightens

    September 11, 2026

    Sweden’s NATO missions are at risk if the left wins election, warns PM Kristersson – POLITICO

    September 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.