CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions

unknownknown exploitedpublic exploitCVE-2026-85706
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
GitLab heeft een kwetsbaarheid verholpen in GitLab Community en Enterprise Editions. De kwetsbaarheid bevindt zich in de repository commits API, waarbij een path traversal mogelijk is. Hierdoor kunnen niet-geauthenticeerde gebruikers willekeurige bestanden op het systeem lezen. De oorzaak ligt in onjuiste path confinement gecombineerd met ontbrekende authenticatiecontroles in de API-endpoint. CISA heeft CVE-2026-85706 opgenomen in de Known Exploited Vulnerabilities-catalogus en er is publieke exploitcode beschikbaar. Vooral internetbereikbare, zelfbeheerde GitLab-installaties lopen risico, omdat een aanvaller zonder inloggegevens gevoelige bestanden kan lezen. Werk kwetsbare systemen direct bij naar GitLab 19.1.8, 19.2.6, 19.3.2 of nieuwer en onderzoek de API-logs op verdachte verzoeken met parameters als file.path. Roteer mogelijk blootgestelde credentials wanneer aanwijzingen voor misbruik worden aangetroffen. Controleer bijgevoegde referenties voor de laatste updates.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-09-12
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0367

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-85706coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Kwetsbaarheid verholpen in

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories