← Back to Tech & Science

Critical GitLab Flaw Exploited Globely Within Hours of Disclosure

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SEPT. 13, 2026 — A critical security vulnerability in the widely used software development platform GitLab is being actively exploited worldwide, allowing attackers to read sensitive files without authentication. The flaw, designated CVE-2026-85706, was disclosed by GitLab on Saturday and immediately targeted by malicious actors within 24 hours of the public announcement.

The vulnerability stems from a path traversal error in GitLab's repository commits API. Security researchers have confirmed that an unauthenticated attacker can execute a single HTTP request to bypass security controls and access arbitrary files on affected servers. This includes sensitive data such as source code, configuration files, and cryptographic credentials stored within self-hosted GitLab instances.

The speed of the exploitation has raised alarms among cybersecurity professionals. WatchTowr researchers reported observing active probes targeting global GitLab installations shortly after the vulnerability details became public. These probes indicate that automated scanning tools are likely being used to identify vulnerable systems and extract data before administrators can apply patches.

In response to the rapid escalation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog. This action mandates federal agencies to remediate the issue immediately and signals the severity of the threat to the broader private sector. CISA officials noted that the nature of the flaw allows for full file reads, creating a high risk of credential theft and subsequent lateral movement within corporate networks.

GitLab stated that the vulnerability affects self-hosted instances globally. The company released patches to address the issue, urging all users to upgrade their systems immediately. However, the window between disclosure and widespread exploitation suggests that many organizations may have already been compromised before receiving the update.

The attack vector relies on manipulating file paths in API requests, a technique that has historically proven difficult for defenders to detect without specific monitoring rules. Because the exploit requires no authentication, it can be launched from any location with internet connectivity against any exposed GitLab server.

As organizations scramble to patch their environments, questions remain regarding the extent of data already exfiltrated. Security teams are investigating whether attackers have successfully harvested credentials that could lead to further breaches in connected systems. The incident underscores the risks associated with rapid vulnerability disclosure and the critical need for immediate patch management in enterprise software infrastructure.

The situation remains fluid as researchers continue to monitor traffic patterns for signs of ongoing exploitation efforts.

Discussion

0 / 2000