NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
GitLab heeft een kwetsbaarheid verholpen in GitLab Community en Enterprise Editions. De kwetsbaarheid bevindt zich in de repository commits API, waarbij een path traversal mogelijk is. Hierdoor kunnen niet-geauthenticeerde gebruikers willekeurige bestanden op het systeem lezen. De oorzaak ligt in onjuiste path confinement gecombineerd met ontbrekende authenticatiecontroles in de API-endpoint. CISA heeft CVE-2026-85706 opgenomen in de Known Exploited Vulnerabilities-catalogus en er is publieke exploitcode beschikbaar. Vooral internetbereikbare, zelfbeheerde GitLab-installaties lopen risico, omdat een aanvaller zonder inloggegevens gevoelige bestanden kan lezen. Werk kwetsbare systemen direct bij naar GitLab 19.1.8, 19.2.6, 19.3.2 of nieuwer en onderzoek de API-logs op verdachte verzoeken met parameters als file.path. Roteer mogelijk blootgestelde credentials wanneer aanwijzingen voor misbruik worden aangetroffen. Controleer bijgevoegde referenties voor de laatste updates.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0367
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-85706Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 65% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85706 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploitedCVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8,…nvd
- criticalexploitedGitLab security advisory (AV26-917)cccs
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- highexploited[NEU] [hoch] GitLab: Mehrere Schwachstellencert-bund
- criticalexploitedCVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerabilitycisa-kev
- unknownexploitedMultiples vulnérabilités dans GitLab (11 septembre 2026)cert-fr-avis
- criticalexploitedGitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8gitlab
Recent advisories for Kwetsbaarheid verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Centerncsc-nl · 2026-09-11
- unknownexploitedNCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-ablencsc-nl · 2026-09-11
- unknownexploitedNCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOSncsc-nl · 2026-09-10
- unknownNCSC-2026-0359 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Endpoint Manager Mobilencsc-nl · 2026-09-09
- unknownNCSC-2026-0357 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Sentryncsc-nl · 2026-09-09
- unknownexploitedNCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chromencsc-nl · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12
- unknownNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-able2026-09-11
- unknownNCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOS2026-09-11