Threat Insight
CVE-2026-85706: Critical GitLab Unauthenticated Arbitrary File Read Vulnerability (CVSS 10.0)
GitLab has released security updates[1] to address CVE-2026-85706, a critical unauthenticated arbitrary file read vulnerability affecting GitLab CE/EE (rated CVSS 10.0).
CVE-2026-85706 affects the POST /api/v4/projects/:id/repository/commits endpoint. Due to the body-upload helper processing the file.path parameter before authentication and failing to restrict it to repository paths, an unauthenticated attacker can cause GitLab to read arbitrary files accessible to the GitLab service process.
The vulnerability can be exploited by URL-encoding one character in the commits route—for example, using %63ommits, which bypasses GitLab Workhorse route handling while Rails still processes the request. When combined with a URL-encoded form request, file contents containing invalid percent-encoding sequences may be reflected in the server’s error response. Other files may still be exposed through an existence or readability oracle.
Successful exploitation could disclose application logs, configuration files, database credentials, gitlab-secrets.json, database.yml, and other sensitive data. Exposed credentials or secrets could enable authenticated access and potentially lead to full GitLab instance compromise. Exploitation requires a reachable vulnerable GitLab instance with at least one public project, but does not require authentication.
CVE
CVE-2026-85706
Affected Products
GitLab CE/EE 18.7 – 19.1.7, 19.2.0 – 19.2.5, 19.3.0 – 19.3.1
Exploitation
The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog[2].
A working proof‑of‑concept (PoC) has been released publicly[3].
Recommended Actions
Truesec recommends upgrading to version 19.1.8, 19.2.6, 19.3.2, or later, and rotating potentially exposed credentials and secrets if the instance was internet-accessible.
References
[1] https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released
[2] https://nvd.nist.gov/vuln/detail/cve-2026-85706
[3] https://github.com/EQSTLab/CVE-2026-85706
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com