CVE-2026-85706 affects the POST /api/v4/projects/:id/repository/commits endpoint. Due to the body-upload helper processing the file.path parameter before authentication and failing to restrict it to repository paths, an unauthenticated attacker can cause GitLab to read arbitrary files accessible to the GitLab service process.
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
The vulnerability can be exploited by URL-encoding one character in the commits route—for example, using %63ommits, which bypasses GitLab Workhorse route handling while Rails still processes the request. When combined with a URL-encoded form request, file contents containing invalid percent-encoding sequences may be reflected in the server’s error response. Other files may still be exposed through an existence or readability oracle.
Successful exploitation could disclose application logs, configuration files, database credentials, gitlab-secrets.json, database.yml, and other sensitive data. Exposed credentials or secrets could enable authenticated access and potentially lead to full GitLab instance compromise. Exploitation requires a reachable vulnerable GitLab instance with at least one public project, but does not require authentication.
CVE
CVE-2026-85706
Affected Products
GitLab CE/EE 18.7 – 19.1.7, 19.2.0 – 19.2.5, 19.3.0 – 19.3.1
Exploitation
The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog[2].
A working proof‑of‑concept (PoC) has been released publicly[3].
Recommended Actions
Truesec recommends upgrading to version 19.1.8, 19.2.6, 19.3.2, or later, and rotating potentially exposed credentials and secrets if the instance was internet-accessible.
References
[1] https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released
[2] https://nvd.nist.gov/vuln/detail/cve-2026-85706
[3] https://github.com/EQSTLab/CVE-2026-85706
The post CVE-2026-85706: Critical GitLab Unauthenticated Arbitrary File Read Vulnerability (CVSS 10.0) appeared first on Truesec.
Article Link: CVE-2026-85706: Critical GitLab Unauthenticated Arbitrary File Read Vulnerability (CVSS 10.0) - Truesec