Defensive self-check · CISA KEV 2026-09-11
GitLab CVE-2026-85706: version and project self-check
CISA added CVE-2026-85706 on 2026-09-11. It is a path-handling issue in the GitLab commits API for Community Edition and Enterprise Edition. Check an instance you operate. This page does not include exploit steps.
Check these three things
- Version. Open Help → Help, or run the admin version page, and compare it with the fixed release in the GitLab advisory.
- Public projects. In Admin → Projects filter on Public and confirm each public project is meant to be public.
- Access logs. Review unusual reads of repository files around 2026-09-11 and later.
What to do
Upgrade to the fixed GitLab release before continuing normal use. If a project was public by mistake, set it back to private and review whether files in it were sensitive.
Vendor record: CISA KEV catalog, entry CVE-2026-85706.