CVE-2026-85706
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
10.0
CVSS 3.1
93.0 %
EPSS (current)
2026-09-11
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: GitLab / Community Edition and Enterprise Edition
Published: 2026-09-12 · Due (CISA): 2026-09-14
CWE: CWE-22 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2026/CVE-2026-85706.yaml | GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read | – |
| metasploit | auxiliary/gather/gitlab_file_read_cve_2026_85706 | auxiliary/gather/gitlab_file_read_cve_2026_85706 | 2026-09-10 |
References only — no downloads or instructions.