
CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules.
GitLab CE/EE Repository Commits API Unauthenticated Path Traversal (CVSS 3.1: 10.0, Critical) Status: Actively exploited in the wild · Listed in CISA KEV (2026-09-11, due 2026-09-14) · Patched by GitLab 2026-09-10
A free, open-source incident response and threat hunting toolkit for CVE-2026-85706 — a critical, unauthenticated path traversal vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) affecting the repository commits API. This repository gives security teams, SOC analysts, detection engineers, and GitLab administrators a ready-to-run IOC (Indicators of Compromise) scanner, Sigma / Suricata / Snort detection rules, Splunk / Elastic / OpenSearch hunting queries, and a step-by-step remediation guide — everything you need to detect exploitation attempts, confirm patch status, and respond to this GitLab zero-day / n-day vulnerability quickly.
🔎 Looking for the fastest path to "am I affected?" Jump to Quick Start.
🚨 Looking for what to patch to? Jump to Fixed Versions & Patch.
| CVE ID | CVE-2026-85706 |
| Vendor / Product | GitLab Community Edition (CE) & Enterprise Edition (EE), self-managed |
| Vulnerability class | Path Traversal (CWE-35), part of the broader Improper Limitation of a Pathname family (CWE-22) |
| Affected component | Repository Commits API (/api/v4/projects/:id/repository/commits...) |
| Root cause | Improper path confinement combined with missing authentication enforcement in the affected API endpoint |
| Affected versions | GitLab CE/EE 18.7 through 19.1.7, 19.2 through 19.2.5, 19.3 through 19.3.1 (last vulnerable patch on each branch; anything on an older, unsupported branch is presumed vulnerable too) |
| Authentication required | None — unauthenticated, pre-auth exploitation |
| Attack vector | Network, single HTTP POST request to the commits API |
| CVSS 3.1 score | 10.0 (Critical) — vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N (Scope Changed, no availability impact — this is a read-only file-disclosure primitive) |
| Impact | Arbitrary file read on the GitLab server — configuration files, secrets, tokens, source code, potentially SSH keys and database credentials |
| Reported by | External security researcher (HackerOne handle "s3ntago"), via GitLab's HackerOne bug bounty program |
| Disclosed / Patched | September 10, 2026 — part of a critical GitLab security release fixing 17–18 vulnerabilities in total, reported variably by different outlets (see Related Vulnerabilities) |
| Estimated exposure | Independent reporting estimates 20,000+ internet-facing self-managed GitLab instances globally were running an affected version at disclosure |
| CISA KEV | Added September 11, 2026; federal civilian remediation due September 14, 2026 (3 calendar days); this places CVE-2026-85706 in CISA's highest-risk tier under Binding Operational Directive (BOD) 26-04 ("Prioritizing Security Updates Based on Risk," effective June 10, 2026, superseding BOD 22-01) — the tier reserved for vulnerabilities that are KEV-listed, publicly exposed, automatable, and capable of yielding full system control, which also mandates forensic triage to determine whether a system was already compromised before patching, not just theoretically exposed |
| Exploitation status | Confirmed active scanning / probing observed in the wild. Reporting on timing varies: watchTowr's initial "Rapid Reaction" write-up is most commonly cited as observing exploitation attempts roughly 24 hours after disclosure, while at least one outlet (citing watchTowr) reports probes beginning within six hours. Either way, the exploitation window from patch to attack was extremely short. |
| Public PoC | Not confirmed publicly available at time of writing |
| GitLab.com / Dedicated | GitLab.com (SaaS) was already patched at disclosure; GitLab Dedicated customers did not need to take action. Only self-managed CE/EE instances require action |
| Official CISA hunting guidance | CISA and multiple outlets (e.g. The Hacker News) specifically recommend reviewing logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing a file.Path parameter — this is exactly the detection logic implemented by this repository's scanner and detection rules |
An unauthenticated attacker can send a single crafted HTTP POST request to
GitLab's repository commits API endpoint
(/api/v4/projects/{id}/repository/commits/), supplying a file.Path
(also seen documented as file.path / file_path) parameter containing
directory-traversal sequences (../, URL-encoded variants, etc.), and have
the server return the contents of arbitrary files outside the intended
repository directory — including GitLab's own secrets file, database
configuration, SSH private keys, and other sensitive server-side data.
Because no credentials are required and the request is trivial to
construct, GitLab and third-party researchers rate this as maximum
severity (CVSS 10.0) and CISA has confirmed active exploitation in
the wild.