GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration

CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab. By Sergio De Simone

devsecurity

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
kev added50
kev short fuse — 3 days to remediate15
epss high20
public poc — 12 repositories20