WorkThe story, in brief

GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration

GitLab self-managed instances are under active attack. If your team runs CE/EE on-prem, patch now—unauthenticated file read is live.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A critical GitLab path-traversal vulnerability (CVE-2026-85706) has moved from theoretical to confirmed active exploitation, enabling unauthenticated remote attackers to exfiltrate arbitrary files from self-managed GitLab CE/EE instances. This affects engineering teams running GitLab on-premises and demands immediate patching.

The key facts

10 to know
  1. CVE-2026-85706: critical path-traversal vulnerability

  2. Affects self-managed GitLab CE/EE

  3. Unauthenticated remote attacker can read arbitrary files

  4. Confirmed active exploitation in the wild

  5. Published October 3, 2026

  6. CVE-2026-85706: path-traversal vulnerability in GitLab CE/EE self-managed

  7. Unauthenticated remote exploitation confirmed in active use

  8. Arbitrary file read capability — source, configs, secrets at risk

  9. Self-managed (on-prem) deployments affected; GitLab.com status not specified in article

  10. Published October 3, 2026; exploitation timeline not disclosed

Go to the source

InfoQ AI/MLinfoq.com

Publisher excerpt: CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab. By Sergio De Simone
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work