One unauthenticated request reads any file on the GitLab server, and the patch taught attackers how
2026-09-12Security
CVE-2026-85706 scores a perfect 10: no authentication, low complexity, arbitrary file read through GitLab's repository commits API. GitLab patched on 10 September. watchTowr saw exploitation attempts the next day, and CISA gave federal agencies until 14 September.