poslední zpráva · zachyceno
SPOJENO PŘES CVE KEV ✓ EPSS 0.93
Multiples vulnérabilités dans GitLab (30 septembre 2026)
De multiples vulnérabilités ont été découvertes dans GitLab. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité. Gitlab indique que la vulnérabilité CVE-2026-85706 est activement exploitée.
GitLab veřejná správa FR CZ NL CA US
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-85706 | 10.0 3.1 · GitLab | KEV ✓ | 0.93 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Jak se o tom psalo 6
-
· zachyceno · CERT-FR – avis FR nadpis události
Multiples vulnérabilités dans GitLab (30 septembre 2026)
De multiples vulnérabilités ont été découvertes dans GitLab. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité. Gitlab indique que la vulnérabilité CVE-2026-85706 est activement exploitée.
-
· CSIRT.CZ (CZ.NIC) CZ
GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat
GitLab vyzval uživatele k okamžité aktualizaci serverů kvůli kritické zranitelnosti CVE-2026-85706 typu path traversal. Chyba v rozhraní API pro revize kódu v repozitářích umožňuje za určitých podmínek neověřenému útočníkovi číst libovolná data ze zranitelného serveru, včetně přihlašovacích údajů a dalších citlivých informací. Společnost watchTowr již zaznamenala pokusy o vyhledávání neaktualizovaných serverů dostupných z internetu. GitLab zranitelnost opravil ve verzích 19.3.2, 19.2.6 a 19.1 a…
-
· NCSC-NL NL
NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions
GitLab heeft een kwetsbaarheid verholpen in GitLab Community en Enterprise Editions. De kwetsbaarheid bevindt zich in de repository commits API, waarbij een path traversal mogelijk is. Hierdoor kunnen niet-geauthenticeerde gebruikers willekeurige bestanden op het systeem lezen. De oorzaak ligt in onjuiste path confinement gecombineerd met ontbrekende authenticatiecontroles in de API-endpoint. CISA heeft CVE-2026-85706 opgenomen in de Known Exploited Vulnerabilities-catalogus en er is publieke…
-
· Cyber Centre Kanada CA
GitLab security advisory (AV26-917)
Serial Number: AV26-917Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.1.8 Prior to 19.2.6 Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…
-
· zachyceno · CISA Advisories US
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements…
-
· zachyceno · CISA KEV US
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVE-2026-85706)
CISA added CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Affected product: GitLab Community Edition and Enterprise Edition. Remediation due date: 2026-09-14.