logo

GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution

ID: 73c30e20-b967-5322-b87a-3173b477f956

STIX ID: report--73c30e20-b967-5322-b87a-3173b477f956

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Abinaya

...
...

GitLab released urgent security updates (19.3.2, 19.2.6, 19.1.8) fixing multiple critical vulnerabilities — notably CVE-2026-85706 (unauthenticated path traversal allowing arbitrary file reads, CVSS 10.0), CVE-2026-87719 (insecure deserialization risking credential/configuration exposure, CVSS 9.9), and CVE-2026-88765 (buffer overflow enabling RCE via project import, CVSS 8.5). Administrators of self-managed instances are strongly urged to upgrade immediately; GitLab.com is already patched and the updates include database migrations that may require downtime for single-node deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.