GitLab CVE-2026-85706 in KEV: check self-managed instances
Review affected GitLab branches, public exposure and potential risks to configuration and CI credentials.
Contents of this article
What is confirmed
CISA added CVE-2026-85706 to KEV on September 11, 2026. GitLab describes a commits API path-traversal and authentication issue that can allow unauthenticated file reads under certain conditions. Self-managed instances should be checked against the advisory.
Match the installed branch
The advisory lists affected releases from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Follow a supported upgrade path and current guidance; these fix points do not cover later vulnerabilities.
Review more than repository content
Inventory active, standby and forgotten test instances, including reverse-proxy targets. If suspicious reads are found, assess configuration, deployment keys and CI credentials. Preserve logs, revoke exposed tokens and review pipeline activity according to the findings.
Verify both hosts and credentials
Verify the running version on every node, then test sign-in, repository access and pipelines. Confirm old credentials fail and replacements have only required permissions. Temporary perimeter controls do not complete these checks.
