Threat Insight

CVE-2026-85706: Critical GitLab Unauthenticated Arbitrary File Read Vulnerability (CVSS 10.0)

GitLab has released security updates[1] to address CVE-2026-85706, a critical unauthenticated arbitrary file read vulnerability affecting GitLab CE/EE (rated CVSS 10.0).

  • Insight
GitLab has released security updates[1] to address CVE-2026-85706, a critical unauthenticated arbitrary file read vulnerability affecting GitLab CE/EE (rated CVSS 10.0).

CVE-2026-85706 affects the POST /api/v4/projects/:id/repository/commits endpoint. Due to the body-upload helper processing the file.path parameter before authentication and failing to restrict it to repository paths, an unauthenticated attacker can cause GitLab to read arbitrary files accessible to the GitLab service process.

The vulnerability can be exploited by URL-encoding one character in the commits route—for example, using %63ommits, which bypasses GitLab Workhorse route handling while Rails still processes the request. When combined with a URL-encoded form request, file contents containing invalid percent-encoding sequences may be reflected in the server’s error response. Other files may still be exposed through an existence or readability oracle.

Successful exploitation could disclose application logs, configuration files, database credentials, gitlab-secrets.json, database.yml, and other sensitive data. Exposed credentials or secrets could enable authenticated access and potentially lead to full GitLab instance compromise. Exploitation requires a reachable vulnerable GitLab instance with at least one public project, but does not require authentication.

CVE

CVE-2026-85706

Affected Products

GitLab CE/EE 18.7 – 19.1.7, 19.2.0 – 19.2.5, 19.3.0 – 19.3.1

Exploitation

The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog[2].

A working proof‑of‑concept (PoC) has been released publicly[3].

Recommended Actions

Truesec recommends upgrading to version 19.1.8, 19.2.6, 19.3.2, or later, and rotating potentially exposed credentials and secrets if the instance was internet-accessible.

References

[1] https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released
[2] https://nvd.nist.gov/vuln/detail/cve-2026-85706
[3] https://github.com/EQSTLab/CVE-2026-85706

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights