Skip to content
cve — cve-2026-85706

grep -rl "CVE-2026-85706" ./articles

CVE-2026-85706

CVE-2026-85706 scores a perfect 10: no authentication, low complexity, arbitrary file read through GitLab's repository commits API. GitLab patched on 10 September. watchTowr saw exploitation attempts the next day, and CISA gave federal agencies until 14 September.

1 article — 2026-09-12

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered