[CVE-2026-85706] GitLab has remediated an issue in GitLab CE/EE affecting all ⚠️在野利用

CVE-2026-85706 | CVSS: 10 | 严重级别: CRITICAL

⚠️ 该漏洞已被 CISA KEV 收录,确认存在在野利用!

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

参考链接:
https://gitlab.com/gitlab-org/gitlab/-/work_items/627748
https://hackerone.com/reports/3909881
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-

📌 数据来源: NVD 官方 | CISA KEV

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部