GitLabCVE-2026-85706
GitLab: missing authentication
Critical10.0CVE-2026-85706 · Published Sep 12, 2026 · updated Sep 24, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 18.7, < 18.11.12 | 18.11.12 |
| >= 19.0, < 19.0.9 | 19.0.9 | |
| >= 19.1, < 19.1.8 | 19.1.8 | |
| >= 19.2, < 19.2.6 | 19.2.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | GitLab: race condition | Medium6.4 | 19.1.8+2 more |
| Sep 15 | GitLab: remote code execution | High8.5 | 19.1.8+2 more |
| Sep 15 | GitLab: improper authorization | Medium5.3 | 19.1.8+2 more |
| Sep 15 | GitLab: improper input validation | High7.7 | 19.1.8+2 more |
| Sep 15 | GitLab: missing authentication | Medium5.4 | 19.1.8+2 more |
| Sep 12 | GitLab: unsafe deserialization | Critical9.9 | 18.11.12+3 more |