Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Death toll from Philippines ferry fire rises to 76, with more still missing

    September 12, 2026

    Interview with Ouest-France

    September 12, 2026

    10 Best Standing Desks Worth Buying in 2026

    September 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Death toll from Philippines ferry fire rises to 76, with more still missing
    • Interview with Ouest-France
    • 10 Best Standing Desks Worth Buying in 2026
    • GitLab urges users to patch max severity path traversal flaw
    • Crypto Billionaires Hand Reform UK $97M in Record Donations
    • Scientists find Ozempic may slow aging itself
    • US court blocks Trump administration plan to cut disaster agency workforce | Courts News
    • Why brazen museum thefts keep happening nearly a year after Louvre heist
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    GitLab urges users to patch max severity path traversal flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 12, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.

    The security flaw, discovered by a security researcher using the ‘s3ntago‘ handle and reported via GitLab’s HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API.

    Unauthenticated attackers can exploit CVE-2026-85706 “under certain conditions” to read arbitrary data (e.g., credentials, secrets, and sensitive information) from vulnerable servers.

    While GitLab has yet to flag this flaw as exploited in the wild, one day later, cybersecurity company watchTowr reported that attackers have already begun searching for Internet-exposed GitLab servers unpatched against CVE-2026-85706.

    “watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,” it warned.

    “Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to ‘/api/v4/projects/{id}/repository/commits/’ URIs containing ‘file.path’ parameters to identify potential exploitation attempts.”

    Yesterday, GitLab patched a second critical vulnerability tracked as CVE-2026-87719 that stems from an insecure deserialization weakness in the GraphQL subscription serializer.

    CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.

    Admins warned to patch as soon as possible

    GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.

    “These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately,” the company warned on Thursday. “GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action.”

    In May 2023, GitLab addressed another maximum severity path traversal flaw (CVE-2023-2825) that exposes sensitive data, including proprietary software code, user credentials, tokens, and files on unpatched servers.

    One year later, CISA and the FBI urged software companies to weed out path traversal security vulnerabilities from their products before shipping, saying that such flaws “have been called ‘unforgivable’ since at least 2007.”

    More recently, in January, GitLab also patched a high-severity two-factor authentication bypass affecting community and enterprise editions that enables attackers who know the target’s account ID to circumvent two-factor authentication.

    Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged four GitLab vulnerabilities as exploited in attacks, including two (CVE-2021-22175 and CVE-2021-39935) in February this year.

    The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.

    Update September 11, 09:39 EDT: Added watchTowr’s report of CVE-2026-85706 probing.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Flaw GitLab Max patch path severity traversal urges users
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

    GPT-6 Astra Users Say OpenAI’s Newest Model Got Dumber. It Happened Before, Too

    CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    Surfshark Systems Targeted by Hackers

    Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

    Check Point Patches Critical VPN Vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Death toll from Philippines ferry fire rises to 76, with more still missing

    September 12, 2026

    Interview with Ouest-France

    September 12, 2026

    10 Best Standing Desks Worth Buying in 2026

    September 12, 2026

    GitLab urges users to patch max severity path traversal flaw

    September 12, 2026
    Latest Posts

    Washington’s Badger Mountain Solar Project Canceled by Developer — ProPublica

    August 3, 2026

    Rejected Wisconsin data center proposal had guaranteed tax revenue, housing

    August 3, 2026

    EIG’s MidOcean Energy lines up new investment as NYK spreads its LNG wings

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Death toll from Philippines ferry fire rises to 76, with more still missing

    September 12, 2026

    Interview with Ouest-France

    September 12, 2026

    10 Best Standing Desks Worth Buying in 2026

    September 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.