logo

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

ID: e92877af-7fcb-55d8-9db6-23995e58b757

STIX ID: report--e92877af-7fcb-55d8-9db6-23995e58b757

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Divya

...
...

GitLab released emergency security updates (19.3.2, 19.2.6, 19.1.8) to remediate multiple critical and high-severity vulnerabilities — notably CVE-2026-85706 (CVSS 10.0 unauthenticated path traversal enabling arbitrary-file reads), CVE-2026-87719 (CVSS 9.9 GraphQL deserialization exposing Advanced Search configuration and credentials), and CVE-2026-88765 (high-severity buffer overflow in project imports with potential RCE) — and urged self-managed administrators to upgrade immediately and review logs, API and project-import activity for suspicious behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.