GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration
CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab. By Sergio De Simone
Sources
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| kev added | 50 |
| kev short fuse — 3 days to remediate | 15 |
| epss high | 20 |
| public poc — 12 repositories | 20 |