News

GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration

  • Sergio De Simone--InfoQ.com
  • published date: 2026-10-03 16:00:00 UTC

CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLa…

Continue Reading at InfoQ.com →