HLD Shield · Security briefing · 21 September 2026Active exploitation

Critical GitLab flaw is being exploited. HLD was unaffected.

CVE-2026-85706 is a critical path-traversal vulnerability in self-managed GitLab Community and Enterprise editions. Under certain conditions, an unauthenticated attacker can read arbitrary files from a vulnerable server through the repository commits API. CISA has added the flaw to its Known Exploited Vulnerabilities catalog.

HLD impact: none

HLD systems and customer services were not affected. Our reviewed production and source-control environment does not operate a vulnerable self-managed GitLab instance, and no GitLab remote is used by this website project. No customer action is required in relation to HLD services.

What happened

GitLab released emergency patches on 10 September 2026. The vulnerability carries a CVSS score of 10.0 and affects GitLab CE and EE from version 18.7: releases before 19.1.8, 19.2.6, and 19.3.2 are vulnerable. GitLab.com and GitLab Dedicated were already patched by GitLab; the urgent action is for operators of self-managed installations.

This is more accurately described as active exploitation of a product vulnerability than a confirmed platform-wide breach of GitLab. A successful attack may expose configuration files, credentials, tokens, or other secrets readable by the GitLab server account, so patching alone may not be sufficient where exploitation is suspected.

What self-managed GitLab operators should do

  1. 1Upgrade self-managed GitLab immediately to 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
  2. 2Use GitLab’s published detections to review repository commits API traffic for local-file inclusion attempts.
  3. 3If an affected instance was internet-facing, investigate for file access and rotate any credentials or secrets that may have been exposed.