GitLab: Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab: Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab Patches Critical Vulnerabilities in Emergency Security Update

GitLab released an emergency security update on September 10, 2026, addressing two critical vulnerabilities and a high-severity flaw that could lead to unauthenticated file disclosure, credential theft, and remote code execution (RCE).

The patched versions 19.3.2, 19.2.6, and 19.1.8 apply to GitLab Community Edition (CE) and Enterprise Edition (EE). While GitLab.com has already been updated, self-managed instances must be upgraded immediately. GitLab Dedicated customers require no action.

Critical Vulnerabilities

  1. CVE-2026-85706 (CVSS 10.0) – A path-traversal flaw in the repository commits API allows unauthenticated attackers to read arbitrary files from GitLab servers, potentially exposing secrets, tokens, and configuration data. This affects CE/EE versions 18.7 and later.
  2. CVE-2026-87719 (CVSS 9.9) – An authenticated GraphQL subscription flaw in GitLab EE (18.3+) could let attackers bypass serialization controls, accessing Advanced Search configurations and sensitive credentials.

High-Severity RCE Risk

  • CVE-2026-88765 (CVSS 8.5) – A buffer overflow in Unicode conversion during Advanced Search indexing could allow authenticated users to trigger RCE via a maliciously crafted Git project export. This affects EE versions 12.3 and later.

Additional Fixes

The update also resolves:

  • Protected CI/CD variable exposure
  • SAML SSO bypasses
  • Stored/reflected XSS vulnerabilities
  • Package registry tampering risks
  • GraphQL denial-of-service (DoS) flaws

Affected Versions & Mitigation

Administrators should upgrade to the latest patched versions:

  • 19.3 → 19.3.2
  • 19.2 → 19.2.6
  • 19.1 → 19.1.8

Security teams are advised to review logs for suspicious activity, including API calls, project imports, and GraphQL requests. Older unsupported branches should transition to a patched release as soon as possible.

Source: https://gbhackers.com/critical-gitlab-flaws/

GitLab TPRM report: https://www.rankiteo.com/company/gitlab-com

"id": "git1789130145",
"linkid": "gitlab-com",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Users of GitLab CE/EE versions '
                                              '18.7+, 18.3+, and 12.3+',
                        'industry': 'Technology/DevOps',
                        'location': 'Global',
                        'name': 'GitLab',
                        'size': 'Large',
                        'type': 'Software Provider'}],
 'attack_vector': ['API Abuse',
                   'GraphQL Exploitation',
                   'Path Traversal',
                   'Buffer Overflow'],
 'customer_advisories': 'Users of affected GitLab versions urged to apply '
                        'patches and review logs',
 'data_breach': {'data_exfiltration': 'Possible via path-traversal flaw '
                                      '(CVE-2026-85706)',
                 'sensitivity_of_data': 'High (secrets, tokens, credentials)',
                 'type_of_data_compromised': ['Secrets',
                                              'Tokens',
                                              'Configuration Data',
                                              'Credentials',
                                              'Protected CI/CD Variables']},
 'date_publicly_disclosed': '2026-09-10',
 'date_resolved': '2026-09-10',
 'description': 'GitLab released an emergency security update addressing two '
                'critical vulnerabilities and a high-severity flaw that could '
                'lead to unauthenticated file disclosure, credential theft, '
                'and remote code execution (RCE). The patched versions 19.3.2, '
                '19.2.6, and 19.1.8 apply to GitLab Community Edition (CE) and '
                'Enterprise Edition (EE). Self-managed instances must be '
                'upgraded immediately.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'critical vulnerabilities',
            'data_compromised': ['Secrets',
                                 'Tokens',
                                 'Configuration Data',
                                 'Credentials',
                                 'Protected CI/CD Variables'],
            'identity_theft_risk': 'High (due to credential theft and PII '
                                   'exposure)',
            'operational_impact': 'Potential unauthorized access and remote '
                                  'code execution on affected systems',
            'systems_affected': ['GitLab Community Edition (CE)',
                                 'GitLab Enterprise Edition (EE)',
                                 'Self-managed GitLab instances']},
 'investigation_status': 'Resolved (patches released)',
 'lessons_learned': 'Importance of timely patching and monitoring for '
                    'API/GraphQL abuse in DevOps platforms',
 'post_incident_analysis': {'corrective_actions': ['Patching vulnerabilities',
                                                   'Enhanced input validation '
                                                   'for API/GraphQL endpoints'],
                            'root_causes': ['Path-traversal flaw in repository '
                                            'commits API',
                                            'Authenticated GraphQL '
                                            'subscription flaw',
                                            'Buffer overflow in Unicode '
                                            'conversion']},
 'recommendations': ['Upgrade to patched versions immediately',
                     'Review logs for suspicious activity',
                     'Transition from unsupported branches to patched '
                     'releases'],
 'references': [{'date_accessed': '2026-09-10',
                 'source': 'GitLab Security Advisory'}],
 'response': {'communication_strategy': 'Public disclosure and advisory for '
                                        'users',
              'containment_measures': ['Release of patched versions (19.3.2, '
                                       '19.2.6, 19.1.8)',
                                       'Immediate upgrade recommendation for '
                                       'self-managed instances'],
              'enhanced_monitoring': 'Recommended log review for API calls, '
                                     'project imports, and GraphQL requests',
              'incident_response_plan_activated': 'Yes (emergency security '
                                                  'update released)',
              'remediation_measures': ['Patching vulnerabilities',
                                       'Reviewing logs for suspicious '
                                       'activity']},
 'stakeholder_advisories': 'Administrators of self-managed GitLab instances '
                           'advised to upgrade immediately',
 'title': 'GitLab Patches Critical Vulnerabilities in Emergency Security '
          'Update',
 'type': ['Data Breach', 'Remote Code Execution', 'Privilege Escalation'],
 'vulnerability_exploited': ['CVE-2026-85706',
                             'CVE-2026-87719',
                             'CVE-2026-88765']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.