CVE-2026-85706CISA KEVEPSS p99.8%

CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

GitLab / Community Edition and Enterprise Edition

Description

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

Scoring

CVSS 10.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS92.96% probability of exploitation · percentile 99.8% · 2026-10-01T12:00:22Z
Last modified2026-09-24

CISA KEV entry

Added to KEV: 2026-09-11

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.