Maximum-Severity GitLab Flaw Under Active Attack Within Hours of Disclosure
GitLab has released patches for several security flaws, including a maximum-severity vulnerability (CVE-2026-85706, CVSS 10.0) in its repository commits API. The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server, provided at least one public project exists on that instance. Security researchers at watchTowr say active probing began within hours of the disclosure, with attackers using the flaw to access log files and configuration files that can contain credentials, secrets, and other sensitive information.
This marks the second critical GitLab vulnerability disclosed in recent weeks, following an actively exploited GraphQL code injection flaw. Researchers note that GitLab instances are an attractive target because successful exploitation can expose source code, CI/CD secrets, and credentials, potentially allowing attackers to tamper with software build pipelines and compromise anything downstream.
GitLab has also patched a separate critical flaw (CVE-2026-87719, CVSS 9.9) affecting the Enterprise Edition, which involves insecure deserialization that could let an authenticated user with Duo Chat access obtain sensitive configuration data and credentials. Patches are available in versions 19.3.2, 19.2.6, and 19.1.8.