Skip to main content
GitLabSecurity incident

Perfect-10 GitLab bug under attack days after patch lands

What happened

GitLab is experiencing active exploitation of a maximum-severity vulnerability (CVE-2026-85706) in its Community and Enterprise Editions, allowing unauthenticated attackers to read arbitrary files from servers.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

security CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10. The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. The vulnerability is a path traversal bug in the repository commits API affecting GitLab Community Edition and Enterprise Edition. GitLab rates it a perfect 10.0, the maximum score on the CVSS v3.1 severity scale. Under certain conditions, an attacker doesn't need to log in before abusing the flaw to read arbitrary files from the GitLab server. GitLab blamed the problem on improper path confinement combined with missing authentication enforcement in the affected API. That's not an especially comforting combination on a platform that can be stuffed with source code, configuration files, and credentials. GitLab shipped fixes on September 10 in versions 19.3.2, 19.2.6 and 19.1.8, and urged operators of affected self-managed installations to upgrade immediately. The bug affects versions from 18.7 before 19.1.8, the 19.2 branch before 19.2.6, and 19.3 before 19.3.2. GitLab.com is already patched, while GitLab Dedicated customers don't need to take...

Keep reading with a free account

The rest of this article, and every signal for GitLab, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
CVE-2026-85706, a path traversal bug in the repository commits API

Extraction

Confidence
100%
Detected
Sep 14, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for GitLab and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at GitLab this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/195820ec-df0c-23ee-da90-b570fdc3cb5a returns this record as JSON. POST /v1/companies/enrich returns every signal for gitlab.com.

{
  "signal_id": "195820ec-df0c-23ee-da90-b570fdc3cb5a",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-14T14:30:00+00:00",
  "company": {
    "name": "GitLab",
    "domain": "gitlab.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands/5296176",
    "title": "Perfect-10 GitLab bug under attack days after patch lands",
    "excerpt": "security CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10. The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog . The vulnerability is a path traversal bug in the repository commits API affecting GitLab Community Edition and Enterprise Edition. GitLab rates it a perfect 10.0, the maximum score on the CVSS v3.1 severity scale. Under certain conditions, an attacker doesn't need to log in before abusing the flaw to read arbitrary files from the GitLab server. GitLab blamed the problem on improper path confinement combined with missing authentication enforcement in the affected API. That's not an especially comforting combination on a platform that can be stuffed with source code, configuration files, and credentials. GitLab shipped fixes on September 10 in versions 19.3.2, 19.2.6 and 19.1.8, and urged operators of affected self-managed installations to upgrade immediately. The bug affects versions from 18.7 before 19.1.8, the 19.2 branch before 19.2.6, and 19.3 before 19.3.2. GitLab.com is already patched, while GitLab Dedicated customers don't need to take...",
    "summary": "GitLab is experiencing active exploitation of a maximum-severity vulnerability (CVE-2026-85706) in its Community and Enterprise Editions, allowing unauthenticated attackers to read arbitrary files from servers.",
    "planning": false,
    "image_url": "https://image.theregister.com/5279434.jpg?imageId=5279434&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 1,
    "published_at": "2026-09-14T14:30:00Z",
    "vulnerability": "CVE-2026-85706, a path traversal bug in the repository commits API",
    "article_sentence": "CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.