The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of a maximum-severity vulnerability in GitLab, the DevSecOps platform used by more than half of Fortune 100 companies and over 30 million registered users worldwide.
The flaw, tracked as CVE-2026-85706, stems from missing authentication enforcement and improper path confinement in GitLab’s repository commits API. Unauthenticated attackers can exploit it with a single HTTP request to read arbitrary files from vulnerable servers, including credentials and other sensitive secrets.
GitLab shipped fixes in Community Edition and Enterprise Edition versions 19.3.2, 19.2.6, and 19.1, urging immediate patching. At the time of release, the company had not flagged the bug as exploited in the wild.
From Patch to Exploitation in a Day
That changed quickly. One day after the fix, security firm watchTowr reported observing internet-wide probing for unpatched GitLab instances. The firm warned that based on the pattern of prior GitLab vulnerabilities, indiscriminate exploitation was likely imminent, and advised defenders to hunt through logs for HTTP POST requests to repository commits API endpoints containing suspicious file path parameters.
CISA subsequently added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog, triggering Binding Operational Directive (BOD) 26-04, which gives federal civilian agencies three days to remediate the flaw.
While BOD 26-04 legally applies only to federal agencies, CISA reiterated that these types of vulnerabilities are frequent attack vectors and urged all organizations, public and private, to prioritize remediation of catalog entries as part of a risk-based vulnerability management program.
Pattern of Repeat Targeting
This marks the fourth GitLab vulnerability CISA has added to its exploited catalog since November 2021, following two separate flaws added in February of this year. GitLab also patched a high-severity two-factor authentication bypass earlier this year that allowed attackers who knew a target’s account ID to circumvent 2FA protections.
- Affected versions: GitLab CE/EE prior to 19.3.2, 19.2.6, and 19.1
- Action required: Patch immediately; federal agencies must remediate within the BOD 26-04 window
- Detection tip: Review logs for POST requests to repository commits API endpoints containing file path parameters
