# GitLab patches maximum-severity file-read flaw as probes hit exposed servers

_Friday, September 11, 2026 at 12:30 PM EDT · Security, Infrastructure · Developing · Tier 1 — Major_

![GitLab patches maximum-severity file-read flaw as probes hit exposed servers — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioFH6aWhF9NgRW1O3yFExc7paTA9akN5-3IUQF8mvEiSTaFJjKvm6YQzFX6MP2uimYplHe1MJXz6eZtPtnxaLy25jJBhU6KuhsWFpIlnqhbn6OI6QTcfp6Olp1-VDUEF4KEYFF7hQDBdmgtxibsg9MkvbcOJIlR8Of2Flyw2m9zYfXC6gUm-TV8XA6vU43/s1700-nu-rw-lo-l85-e365/gitlab-wild.jpg)

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said.

The vulnerability, tracked as CVE-2026-85706 with a CVSS score of 10.0, stems from improper path confinement and missing authentication enforcement in that API. GitLab also patched a critical insecure deserialization bug in its Enterprise Edition that could expose instance configurations and credentials. Security firm watchTowr said it observed active in-the-wild probes against the flaw beginning the morning of September 11, 2026, and warned that mass exploitation is likely.

Organizations running internet-exposed self-managed GitLab instances are urged to patch or restrict public access.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html)
- [BleepingComputer](https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/)

---
Canonical: https://techandbusiness.org/newswire/M5PV0bKAzSmHFrK4QQ-CCJ
Retrieved: 2026-09-12T02:49:22.948Z
Publisher: Tech & Business (techandbusiness.org)
