Maximum-Severity GitLab Flaw Threatens Software Supply Chains
A newly disclosed vulnerability in GitLab, tracked as CVE-2026-85706, has received the highest possible severity score of 10 out of 10. The flaw is a path traversal issue affecting both GitLab Community Edition and Enterprise Edition, meaning it can impact organisations using either the free or paid versions of the popular software development platform.
Because GitLab is widely used to store and manage source code, a vulnerability of this severity raises serious concerns for software supply chain security. Attackers exploiting a path traversal flaw could potentially access files or systems outside their intended permissions, opening the door to code tampering, data theft, or further compromise of connected systems.
Details on active exploitation are limited at this stage, but the maximum severity rating means organisations running GitLab should treat this as an urgent priority for patching once official fixes are available.