Exploited Vulnerabilities Daily
🌐 Nederlands

← Alle nieuwe vermeldingen

CVE-2026-85706: GitLab Community Edition and Enterprise Edition

GitLab Community Edition en Enterprise Edition bevat een path traversal kwetsbaarheid waarmee een ongeauthenticeerde gebruiker willekeurige bestanden kan lezen als gevolg van een onjuiste opsluiting van het pad en ontbrekende authenticatie handhaving in de repository commits API.

CISA (English)

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

Leverancier
GitLab
Product
Community Edition and Enterprise Edition
Kwetsbaarheid
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Toegevoegd op
11 sep 2026
CISA-termijn (Amerikaanse federale instanties)
14 sep 2026
Bekend gebruik in ransomwarecampagnes
Onbekend
Zwakte (CWE)
CWE-35

Referenties

Deze site vat de CISA-catalogus alleen ter informatie samen. Het is geen beveiligingsadvies – volg de richtlijnen van uw leverancier en officiële adviezen.

Laatst bijgewerkt: · Catalogusversie 2026.10.02