Defensive self-check · CISA KEV 2026-09-11

GitLab CVE-2026-85706: version and project self-check

CISA added CVE-2026-85706 on 2026-09-11. It is a path-handling issue in the GitLab commits API for Community Edition and Enterprise Edition. Check an instance you operate. This page does not include exploit steps.

Check these three things

  • Version. Open Help → Help, or run the admin version page, and compare it with the fixed release in the GitLab advisory.
  • Public projects. In Admin → Projects filter on Public and confirm each public project is meant to be public.
  • Access logs. Review unusual reads of repository files around 2026-09-11 and later.

What to do

Upgrade to the fixed GitLab release before continuing normal use. If a project was public by mistake, set it back to private and review whether files in it were sensitive.

Vendor record: CISA KEV catalog, entry CVE-2026-85706.