URL has been copied successfully!
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read Exploited Within 24 Hours
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]

First seen on securityaffairs.com

Jump to article: securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link