Self-managed GitLab flaw reportedly allows file reads without a login
DailyCVEBrief says CVE-2026-85706 was patched September 10, 2026, but warns that patching cannot undo earlier file reads and recommends rotating secrets.
TLDR
DailyCVEBrief describes CVE-2026-85706 as an unauthenticated arbitrary file-read flaw affecting only self-managed GitLab CE/EE, with a CVSS severity score of 10.0. It reports a September 10, 2026 patch, a Known Exploited Vulnerabilities listing on September 11 and probing that same day. The account says there is no workaround and urges users to rotate secrets because patching cannot undo any file reads that already occurred.
Combined views
84
2 Sources, first seen ago