discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

GitLab urges users to patch max severity path traversal flaw

GitLab urges immediate patching of a max severity path traversal vulnerability.

By Sergiu Gatlan·Sep 11·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

GitLab urges users to patch max severity path traversal flaw
Image: bleepingcomputer.com

GitLab has patched two critical vulnerabilities, including a path traversal flaw that could expose sensitive data. WatchTowr warns of in-the-wild probes for the latest critical GitLab Path Traversal vulnerability.

Why it matters

This vulnerability could allow attackers to read arbitrary files from unpatched servers, posing a significant security risk.

GitLab found a way to break into servers and read secret information. They told people to fix their servers quickly to stop bad guys from doing it.

Analysis

Background

  • CVE-2026-85706: A path traversal vulnerability discovered by a security researcher and reported via GitLab's bug bounty program.
  • CVE-2026-87719: An insecure deserialization weakness affecting GitLab EE and allowing unauthorized access to sensitive credentials.

Impact

  • CVE-2026-85706: Unauthenticated attackers can exploit this flaw to read arbitrary data from vulnerable servers.
  • CVE-2026-87719: Authenticated users with Duo Chat access can steal sensitive credentials and instance configurations.

Timeline

  • Discovery: Reported by a security researcher using the 's3ntago' handle.
  • Patching: GitLab patched the vulnerabilities in versions 19.3.2, 19.2.6, and 19.1 of GitLab Community Edition (CE) and Enterprise Edition (EE).

WatchTowr Report

  • WatchTowr warned of in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706.
  • They observed attackers searching for unpatched GitLab servers.

Future Outlook

  • GitLab urges immediate patching of the vulnerabilities to prevent exploitation.
  • CISA and the FBI have previously flagged GitLab vulnerabilities as exploited in attacks.

Conclusion

  • GitLab's patching efforts are crucial to mitigating the risk of data breaches and unauthorized access.

Key points

  • GitLab patched two critical vulnerabilities, including a path traversal flaw.
  • CVE-2026-85706 allows attackers to read arbitrary files from unpatched servers.
  • CVE-2026-87719 allows authenticated users to steal sensitive credentials.
  • GitLab urges immediate patching to prevent exploitation.
  • CISA and the FBI have previously flagged GitLab vulnerabilities as exploited in attacks.
The Upside

The quick patching of these vulnerabilities will prevent attackers from reading sensitive data.

The Downside

If people don't patch their servers quickly, attackers might still be able to read secret information.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritygitlabvulnerabilitypath-traversalsecurity-vulnerability

Author

Sergiu Gatlan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 11, 2026

Source

bleepingcomputer.com

Share

Topics

securitygitlabvulnerabilitypath-traversalsecurity-vulnerability

Related

More from this desk

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.

Oct 7·krebsonsecurity.com

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Jordanian teenager detained for leading ShinyHunters, a data theft and extortion group. FBI investigating extortion of Boeing subsidiary Jeppesen ForeFlight.

Oct 7·schneier.com

Apple’s Verified Photography System

Apple introduces a new system called 'Reference Image' to verify iPhone photos without tying them to specific devices or photographers.