← nejvýznamnější zprávy

SPOJENO AI KEV ✓ EPSS 0.15

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September…

13 zpráv z 13 zdrojů · první 10. 9. 02:00 · poslední 15. 9. 11:51 CZ · EN/orig

GitLab veřejná správa CZ US NL FI SK SE CA IT FR

tg: zneužíváno tg: zranitelnost tg: regulace tg: novinka v produktu tp: DDoS

CVE v události 8

CVEhodnoceníKEVEPSS
CVE-2025-14871 7.5 3.1 · GitLab 0.01
CVE-2026-1168 7.5 3.1 · GitLab 0.01
CVE-2026-13210 7.7 3.1 · GitLab 0.00
CVE-2026-78252 8.2 3.1 · GitLab 0.00
CVE-2026-79708 8.5 3.1 · GitLab 0.00
CVE-2026-85706 10.0 3.1 · GitLab KEV ✓ 0.15
CVE-2026-87719 9.9 3.1 · GitLab 0.01
CVE-2026-88765 8.5 3.1 · GitLab 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Dalších 2 CVE zmiňuje jen text zpravodajského článku (CVE-2021-22175, CVE-2021-39935). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.

Jak se o tom psalo 13

  1. · CSIRT.CZ (CZ.NIC) CZ

    GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat

    GitLab vyzval uživatele k okamžité aktualizaci serverů kvůli kritické zranitelnosti CVE-2026-85706 typu path traversal. Chyba v rozhraní API pro revize kódu v repozitářích umožňuje za určitých podmínek neověřenému útočníkovi číst libovolná data ze zranitelného serveru, včetně přihlašovacích údajů a dalších citlivých informací. Společnost watchTowr již zaznamenala pokusy o vyhledávání neaktualizovaných serverů dostupných z internetu. GitLab zranitelnost opravil ve verzích 19.3.2, 19.2.6 a 19.1 a…

  2. · Rapid7 US nadpis události

    CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

    OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September…

  3. · BleepingComputer US

    CISA: Hackers now exploit max severity GitLab flaw in attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]

  4. · NCSC-NL NL

    NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions

    GitLab heeft een kwetsbaarheid verholpen in GitLab Community en Enterprise Editions. De kwetsbaarheid bevindt zich in de repository commits API, waarbij een path traversal mogelijk is. Hierdoor kunnen niet-geauthenticeerde gebruikers willekeurige bestanden op het systeem lezen. De oorzaak ligt in onjuiste path confinement gecombineerd met ontbrekende authenticatiecontroles in de API-endpoint. CISA heeft CVE-2026-85706 opgenomen in de Known Exploited Vulnerabilities-catalogus en er is publieke…

  5. · NCSC-FI FI

    GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-85706, CVE-2026-87719, CVE-2026-88765, CVE-2026-79708, CVE-2026-78252, CVE-2026-13210, CVE-2025-14871, CVE-2026-1168, CVE-2024-11222, CVE-2026-12910, CVE-2026-82837, CVE-2026-19619, CVE-2026-86341, CVE-2026-86340, CVE-2026-7514, CVE-2026-8030, CVE-2026-16794, CVE-2026-3855, Summary: On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE)…

  6. · SK-CERT (NBÚ SR) SK

    VAROVANIE: Kritické zraniteľnosti GITLAB CE a EE

    Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred kritickými zraniteľnosťami v produktoch GitLab Community Edition (CE) a GitLab Enterprise Edition (EE). Uvedené zraniteľnosti možno zneužiť na získanie neoprávneného prístupu k citlivým údajom a úplné narušenie dôvernosti, integrity a dostupnosti systémov. Vývojári GitLab 10. septembra 2026 vydali bezpečnostné aktualizácie, ktoré opravujú až 18 zraniteľností, z ktorých 2 sú... The post VAROVANIE: Kritické zraniteľnosti GITLAB CE a…

  7. · CERT-SE SE

    GitLab rättar kritiska sårbarheter

    GitLab har publicerat säkerhetsuppdateringar för flera sårbarheter i GitLab Community Edition (CE) och Enterprise Edition (EE). [1] Två av dessa sårbarheter, CVE-2026-85706 och CVE-2026-87719, klassas som kritiska.

  8. · Cyber Centre Kanada CA

    GitLab security advisory (AV26-917)

    Serial Number: AV26-917Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.1.8 Prior to 19.2.6 Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…

  9. · CSIRT Itálie (ACN) IT

    Risolte vulnerabilità in GitLab CE/EE

    Aggiornamenti di sicurezza rilasciati per GitLab, nota piattaforma per la gestione del ciclo di sviluppo software e della collaborazione sui progetti, sanano alcune vulnerabilità, di cui 2 con gravità "critica" e 6 con gravità "alta"

  10. · CISA Advisories US

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements…

  11. · CISA KEV US

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVE-2026-85706)

    CISA added CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Affected product: GitLab Community Edition and Enterprise Edition. Remediation due date: 2026-09-14.

  12. · CERT-FR – avis FR

    Multiples vulnérabilités dans GitLab (11 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

  13. · GitLab Security US

    GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

    On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of…