GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration
GitLab self-managed instances are under active attack. If your team runs CE/EE on-prem, patch now—unauthenticated file read is live.

Why it matters
A critical GitLab path-traversal vulnerability (CVE-2026-85706) has moved from theoretical to confirmed active exploitation, enabling unauthenticated remote attackers to exfiltrate arbitrary files from self-managed GitLab CE/EE instances. This affects engineering teams running GitLab on-premises and demands immediate patching.
The key facts
10 to knowCVE-2026-85706: critical path-traversal vulnerability
Affects self-managed GitLab CE/EE
Unauthenticated remote attacker can read arbitrary files
Confirmed active exploitation in the wild
Published October 3, 2026
CVE-2026-85706: path-traversal vulnerability in GitLab CE/EE self-managed
Unauthenticated remote exploitation confirmed in active use
Arbitrary file read capability — source, configs, secrets at risk
Self-managed (on-prem) deployments affected; GitLab.com status not specified in article
Published October 3, 2026; exploitation timeline not disclosed
Go to the source
InfoQ AI/MLinfoq.com
Publisher excerpt: CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab. By Sergio De Simone