---
id: 2026-09-gitlab-cve-2026-85706-unauth-file-read-kev
title: "GitLab CVE-2026-85706 — unauthenticated arbitrary file read via the repository commits API (CVSS 10.0), probed in the wild within a day, CISA KEV; same release fixes a CVSS 9.9 Duo Chat credential leak"
date_disclosed: 2026-09-10
last_updated: 2026-09-12
severity: critical
status: active
ecosystems: [gitlab, self-hosted, ci-cd, source-hosting]
tools_affected: ["GitLab CE/EE self-managed 18.7 – 19.3.1", "GitLab Duo Chat (CVE-2026-87719, EE ≥ 18.3)"]
tags: [cve, cisa-kev, path-traversal, unauthenticated, secrets-exposure, ci-cd, source-hosting, rapid-exploitation, ai-feature]
---

## TL;DR

GitLab's **2026-09-10** critical patch release (19.3.2 / 19.2.6 / 19.1.8) fixes **CVE-2026-85706**: a path-traversal in the **repository commits API** that lets an **unauthenticated** attacker read arbitrary files the GitLab service account can reach — logs and configuration holding credentials, secrets and tokens — in a single HTTP request. GitLab scored it **CVSS 3.1 10.0**; NVD published the same score on 2026-09-12. watchTowr saw in-the-wild probing from **06:00 UTC on 2026-09-11**, one day after disclosure, and **CISA added it to KEV the same day** with a federal remediation deadline of **2026-09-14**. Affected: CE/EE **18.7 → 19.1.7, 19.2.0 → 19.2.5, 19.3.0 → 19.3.1**. GitLab.com and Dedicated are already patched. The same release fixes **CVE-2026-87719** (CVSS **9.9**): an authenticated user with **Duo Chat** access could pull Advanced Search configuration and credentials through a crafted GraphQL subscription.

## What happened

GitLab's patch post describes CVE-2026-85706 as "improper path confinement combined with missing authentication enforcement" in the commits API. watchTowr's rapid-reaction analysis identifies the surface as `POST /api/v4/projects/{id}/repository/commits/` with `file.path` parameters, and The Hacker News (citing watchTowr) adds the one precondition: **at least one public project must exist** on the instance — which is true of most self-managed GitLabs that host anything open-source or any "public" internal sample. What is readable is whatever the GitLab service account can open: GitLab-specific configuration and log files containing credentials, secrets and access tokens, per watchTowr and SecurityWeek. On a self-managed instance that is the host for your source, your CI/CD variables, your runners' registration tokens, and often your deploy keys.

The release fixes 19 CVEs in total. Beyond the headline:

- **CVE-2026-87719** (CVSS 9.9, EE 18.3 → same fixed versions) — an authenticated user with **Duo Chat** access could obtain Advanced Search instance configuration and sensitive credentials via a specially crafted GraphQL subscription. Duo Chat is GitLab's AI assistant; this is another instance of an AI feature widening a reachable surface (compare [PyCharm's unauthenticated Jupyter MCP](2026-08-agent-framework-mcp-cve-batch.md)).
- A buffer overflow in Unicode conversion (CVSS 8.5), a **Developer-role privilege escalation to CI/CD variables** (CVSS 8.5), GraphQL complexity-limiter DoS bugs (7.5), and protected-environment authorisation bypasses (4.4) — per GitLab's release notes.

**Exploitation timeline:** patch and advisory 2026-09-10 → watchTowr probes 2026-09-11 06:00 UTC → CISA KEV 2026-09-11 (confirmed directly in the KEV JSON feed: `dateAdded` 2026-09-11, "GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability") → NVD record 2026-09-12. A one-day disclosure-to-probing gap on a CVSS 10 file read against source-hosting infrastructure is the same shape as the [JFrog Artifactory chain](2026-09-jfrog-artifactory-auth-bypass-chain-kev.md) added to KEV on the same day.

## Am I affected?

Only **self-managed** GitLab. GitLab.com and GitLab Dedicated need no action.

```bash
# Version check (any of these)
sudo gitlab-rake gitlab:env:info 2>/dev/null | grep -i 'GitLab information' -A2
curl -s -H "PRIVATE-TOKEN: $GITLAB_TOKEN" https://gitlab.example.com/api/v4/version
# Vulnerable if: 18.7 <= v < 19.1.8, or 19.2.0 <= v < 19.2.6, or 19.3.0 <= v < 19.3.2

# Hunt for probing/exploitation (watchTowr's guidance): unauthenticated POSTs to the commits API carrying file.path
grep -E 'POST .*/api/v4/projects/[^/]+/repository/commits/?' /var/log/gitlab/gitlab-rails/api_json.log 2>/dev/null | grep -i 'file.path' | head
grep -E '/repository/commits' /var/log/gitlab/nginx/gitlab_access.log 2>/dev/null | grep POST | head
```

If you find matching requests from addresses you do not recognise before you patched, assume every secret the GitLab host holds has been read.

## If you are affected

1. Upgrade to **19.3.2 / 19.2.6 / 19.1.8** now. The release includes database migrations; single-node instances will see downtime. If you cannot upgrade today, take the instance off the public internet until you can.
2. If exploitation is suspected, rotate what GitLab's host and database hold — runner registration tokens, CI/CD variables (especially group/instance-level cloud credentials), deploy keys, integration tokens, and the instance's own secrets — and re-issue personal access tokens: → [playbooks/rotating-cloud-credentials.md](../playbooks/rotating-cloud-credentials.md), → [playbooks/if-your-github-pat-leaked.md](../playbooks/if-your-github-pat-leaked.md) (the token-rotation steps translate directly).
3. Review Duo Chat access if you run EE ≥ 18.3: CVE-2026-87719 needs an authenticated user, so audit which accounts had it and whether any are shared or automation identities.

## Prevention

- → [prevention/ci-cd-hardening.md](../prevention/ci-cd-hardening.md) — keep cloud credentials out of instance-level CI variables; use OIDC federation from runners so a file read on the GitLab host does not yield long-lived keys.
- → [prevention/credential-hygiene.md](../prevention/credential-hygiene.md)
- Do not expose self-managed source hosting to the whole internet if you can avoid it; when you must, put it behind SSO/VPN or an allow-list. This bug needed no account — only reachability plus one public project.
- Subscribe to GitLab's patch-release feed and treat "critical patch release" as a same-day action: the probing started about 24 hours after the post.

## Sources

- [GitLab — Critical Patch Release: 19.3.2, 19.2.6, 19.1.8](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/) — fetched 2026-09-12; vendor advisory, 2026-09-10: CVE-2026-85706 and CVE-2026-87719 descriptions and scores, affected ranges, full list of 19 CVEs, migration/downtime note.
- [watchTowr — Rapid Reaction: GitLab Path Traversal Vulnerability (CVE-2026-85706)](https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/) — fetched 2026-09-12; researcher analysis: vulnerable endpoint and parameter, what is readable, log-hunting guidance.
- [SecurityWeek — GitLab Vulnerability Exploited One Day After Disclosure](https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/) — fetched 2026-09-12; 2026-09-11: watchTowr's in-the-wild observation, KEV addition, source-code/CI-secret impact framing.
- [The Hacker News — GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure](https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html) — fetched 2026-09-12; 2026-09-11: 06:00 UTC probing start, the "at least one public project" precondition, KEV deadline 2026-09-14.
- [NVD — CVE-2026-85706](https://nvd.nist.gov/vuln/detail/CVE-2026-85706) and [NVD — CVE-2026-87719](https://nvd.nist.gov/vuln/detail/CVE-2026-87719) — fetched via the NVD API 2026-09-12; both published 2026-09-12, CVSS 3.1 10.0 and 9.9 respectively.
- [CISA — Known Exploited Vulnerabilities Catalog (JSON feed)](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json) — fetched 2026-09-12; CVE-2026-85706 `dateAdded` 2026-09-11.
