CVE-2026-85706: GitLab Unauthenticated Arbitrary File Read via the Repository Commits API

CVE-2026-85706 is a critical, unauthenticated path traversal vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE).

This article has been indexed from OffSec

Read the original article: