CVE-2026-85706: GitLab Community Edition and Enterprise Edition
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
- 廠商
- GitLab
- 產品
- Community Edition and Enterprise Edition
- 漏洞
- GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- 加入日期
- 2026年9月11日
- CISA 修補期限(美國聯邦機關)
- 2026年9月14日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-35
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02