The Maivia Gazette

Verified AI news, every morning

Security

CISA says attackers are exploiting a maximum-severity GitLab flaw that leaks secrets in one request

CVE-2026-85706 lets unauthenticated users read credentials through the repository commits API; patches shipped Thursday and watchTowr saw probes a day later.

A filing cabinet drawer in an archive corridor has been pulled open through a hole in the wall, spilling papers.
AI-generated illustration, not event photography.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

The US Cybersecurity and Infrastructure Security Agency has warned that hackers are exploiting a maximum-severity vulnerability in GitLab, the DevSecOps platform used by more than half of Fortune 100 companies and by over 30 million registered users. The flaw, tracked as CVE-2026-85706, stems from missing authentication enforcement and improper path confinement in the repository commits API. Unauthenticated attackers can use it to read credentials, secrets, and other sensitive information from vulnerable servers. GitLab fixed the issue on Thursday in Community Edition and Enterprise Edition versions 19.3.2, 19.2.6, and 19.1, and urged users to patch immediately. GitLab itself has not yet tagged the bug as actively exploited. Security firm watchTowr reported one day after the fix that attackers were already probing the internet for unpatched servers, describing the flaw as a path traversal that lets attackers read arbitrary files in a single HTTP request. Based on the history of recent GitLab bugs, watchTowr said indiscriminate exploitation was likely not far away, and advised defenders to hunt through log files for suspicious HTTP POST requests. CISA's warning now confirms that exploitation has begun. Organizations running self-managed GitLab should treat any exposed instance as potentially compromised, rotate secrets stored in affected repositories, and apply the fixed versions.

Sources

  1. BleepingComputerCISA: Hackers now exploit max severity GitLab flaw in attacksPublished · fetched

Also in this edition