GitLab Path Traversal Vulnerability CVE-2026-85706 Exploitation Imminent

🚨 watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request. The vulnerability allows an unauthenticated, external attacker to read local files and configs to obtain credentials, secrets, and sensitive information. Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. Organizations with public-facing self-hosted GitLab instances should patch as soon as possible or remove public access. Defenders should also hunt through log files for HTTP POST requests to "/api/v4/projects/{id}/repository/commits/" URIs containing "file.path" parameters to identify potential exploitation attempts. If you want to understand your organization's exposure to CVE-2026-85706, reach out to us through the watchTowr website or through one of our trusted and authorized partners.

  • No alternative text description for this image

To view or add a comment, sign in

Explore content categories