GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution
ID: 73c30e20-b967-5322-b87a-3173b477f956
STIX ID: report--73c30e20-b967-5322-b87a-3173b477f956
Feed Name: cybersecurityNews.com
GitLab released urgent security updates (19.3.2, 19.2.6, 19.1.8) fixing multiple critical vulnerabilities — notably CVE-2026-85706 (unauthenticated path traversal allowing arbitrary file reads, CVSS 10.0), CVE-2026-87719 (insecure deserialization risking credential/configuration exposure, CVSS 9.9), and CVE-2026-88765 (buffer overflow enabling RCE via project import, CVSS 8.5). Administrators of self-managed instances are strongly urged to upgrade immediately; GitLab.com is already patched and the updates include database migrations that may require downtime for single-node deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
