FortiGuard Labs has observed attack activity targeting CVE-2026-85706, a critical path traversal vulnerability in GitLab Community Edition and Enterprise Edition. The vulnerability affects the repository commits API and can allow an unauthenticated remote attacker to read arbitrary files from a vulnerable GitLab server due to improper path confinement and missing authentication enforcement. The vulnerability carries a CVSS score of 10.0 and requires no privileges or user interaction.
CVE-2026-85706 was added to the CISA Known Exploited Vulnerabilities catalog on September 11, 2026. Public exploit and proof-of-concept material has also emerged, increasing the potential for exploitation against exposed, unpatched GitLab instances.
