ALPHACON BBSGość · pl
← Podatności

Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0

CVE-2026-85706 · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

Identyfikator
CVE-2026-85706
CVSS
10.0 CRITICAL
CISA KEV
AKTYWNIE WYKORZYSTYWANE
Producent
GitLab
Produkt
Community Edition and Enterprise Edition
Dodano do KEV
2026-09-11
Termin CISA
2026-09-14
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.