## Overview
GitLab has released a patch for CVE-2026-85706, a critical vulnerability affecting GitLab CE/EE versions 18.7 through 19.1.8, 19.2 through 19.2.6, and 19.3 through 19.3.2. This flaw could allow unauthenticated users to read arbitrary files from the GitLab server.
## Technical Details
The vulnerability stems from improper path confinement and missing authentication enforcement in the repository commits API. Under certain conditions, an attacker could exploit this weakness to access sensitive files without proper authentication. The issue is rated with a CVSS score of 10.0, indicating its critical nature and potential impact.
## Impact
If exploited, this vulnerability could lead to unauthorized access to sensitive data stored on the GitLab server. Organizations using affected versions are at significant risk, as attackers could gain insights into private repositories or other confidential information.
## Mitigation
Defenders should prioritize updating their GitLab installations to the latest versions. Specifically, users should upgrade to GitLab CE/EE version 19.1.8, 19.2.6, or 19.3.2 or later. Additionally, organizations should review their access controls and monitor for any unusual activity related to their GitLab instances.
CSURFACE Threat Sensor