news.mlab.sh
Back to the feed
vulnerability

GitLab Vulnerability Exploited One Day After Disclosure

Critical
Summary

A critical vulnerability in GitLab, allowing unauthenticated users to read arbitrary files, was exploited just one day after its disclosure. Multiple versions of GitLab are affected, and attackers are actively attempting to exploit the flaw. Upgrading to patched versions is strongly recommended to mitigate the risk.

A newly discovered vulnerability in GitLab, tracked as CVE-2026-85706, has been actively exploited by threat actors shortly after its public announcement. This path traversal issue allows unauthenticated users to read any file on the GitLab server via a single HTTP request. WatchTowr observed the first in-the-wild exploitation attempts on Friday, indicating a rapid response from attackers. GitLab has released patches to address this vulnerability, and multiple versions of GitLab are affected, including Community Edition (CE) and Enterprise Edition (EE) versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. These patches also address 17 other vulnerabilities, including another critical-severity bug, CVE-2026-87719, which is an insecure deserialization issue in the GraphQL subscription serializer. This flaw could allow attackers to access Advanced Search instance configurations and sensitive credentials. The vulnerability is considered critical due to its ease of exploitation and potential for significant damage. GitLab has urged users to upgrade immediately to protect their systems.

Read the full article at SecurityWeek