GitLab has released security fixes for CVE-2026-85706, a critical path traversal vulnerability affecting both GitLab Community Edition (CE) and Enterprise Edition (EE) with a maximum CVSS score of 10.0. The flaw allows unauthorized access to server-side files, risking exposure of sensitive source code and development infrastructure. Following confirmation of its addition to CISA’s Known Exploited Vulnerabilities (KEV) catalog, organizations managing self-hosted GitLab instances are strongly urged to prioritize immediate remediation.





