CVE-2026-85706
- CVSS
- —
- EPSS
- —
- CISA KEV
- Added 2026-09-11, due 2026-09-14
- Exploitation
- No report
- Public exploits
- 12 repositories
- State
- Unknown
Coverage

Actively exploitedDark Reading
Maximum Severity GitLab Flaw Puts Supply Chains at Risk(opens the publisher's site in a new tab)
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

Actively exploitedRapid7
CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild(opens the publisher's site in a new tab)
Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to…
Actively exploitedCanadian Centre for Cyber Security
GitLab security advisory (AV26-917)(opens the publisher's site in a new tab)
Serial Number: AV26-917 Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.1.8 Prior to 19.2.6 Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to…
Actively exploitedCISA advisories & alerts
CISA Adds One Known Exploited Vulnerability to Catalog(opens the publisher's site in a new tab)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber…
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev