• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology

Self-managed GitLab flaw reportedly allows file reads without a login

DailyCVEBrief says CVE-2026-85706 was patched September 10, 2026, but warns that patching cannot undo earlier file reads and recommends rotating secrets.

CVE BriefCB
FIKSCloudFI
2 Sources, 20d ago, first seen 20d ago

TLDR

DailyCVEBrief describes CVE-2026-85706 as an unauthenticated arbitrary file-read flaw affecting only self-managed GitLab CE/EE, with a CVSS severity score of 10.0. It reports a September 10, 2026 patch, a Known Exploited Vulnerabilities listing on September 11 and probing that same day. The account says there is no workaround and urges users to rotate secrets because patching cannot undo any file reads that already occurred.

Combined views

84

2 Sources, first seen 20d ago

2 comments

Combined views

84

2 Sources, first seen 20d ago

2 comments

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

2 Sources

CVE Brief@DailyCVEBriefDEEP DIVE: CVE-2026-85706 is an unauthenticated arbitrary file read in GitLab CE/EE, CVSS 10.0. Patched Sept 10, KEV-listed Sept 11, probed the same day. Self-managed only, and there is no workaround. Patching does not undo what was already read: rotate your secrets.20d
FIKSCloud@fiks_cloudA CVSS 10.0 in self-managed GitLab. No login needed. Exploited within a day of the patch, now on CISA's KEV list. The interesting part isn't the CVE. It's what most teams skip right after patching. 🧵20d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI

    2 Sources

    CVE Brief@DailyCVEBriefDEEP DIVE: CVE-2026-85706 is an unauthenticated arbitrary file read in GitLab CE/EE, CVSS 10.0. Patched Sept 10, KEV-listed Sept 11, probed the same day. Self-managed only, and there is no workaround. Patching does not undo what was already read: rotate your secrets.20d
    FIKSCloud@fiks_cloudA CVSS 10.0 in self-managed GitLab. No login needed. Exploited within a day of the patch, now on CISA's KEV list. The interesting part isn't the CVE. It's what most teams skip right after patching. 🧵20d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet