GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
GitLab CE/EE contains a path traversal flaw in the repository commits API that allows an unauthenticated attacker to read arbitrary files from the server filesystem. Because the API neither enforces authentication nor confines file path parameters to the repository directory, an attacker can retrieve sensitive configuration files such as gitlab.yml, which may contain credentials and secrets enabling further compromise. Self-managed instances running versions from 18.7 through the 19.x series are affected; GitLab.com and Dedicated customers are already patched.
The repository commits API fails on two fronts simultaneously: it does not require authentication before processing requests, and it does not validate that supplied path parameters remain within the intended repository directory. These are classic path traversal conditions under CWE-22 and CWE-35. When an API accepts a caller-controlled path and resolves it against the filesystem without stripping traversal sequences, the effective working directory boundary collapses. The result is that the server treats the traversal payload as a legitimate file reference and returns the contents of whatever file the resolved path points to.
An attacker sends a crafted HTTP request to the commits API endpoint, supplying a path traversal payload in the metadata.path parameter, with no authentication credentials required. The server resolves the path, steps outside the repository root, and returns the contents of the targeted file. Files such as gitlab.yml are directly reachable this way and contain database credentials, secret keys, and integration tokens. No prior access, account, or session is needed; network reachability to the API is the only precondition, making internet-exposed self-managed instances immediately at risk.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If GitLab Community Edition and Enterprise Edition runs inside your authorization boundary, yes. CVE-2026-85706 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its September 14, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. Your path forward is remediation now, or formally documented mitigation with a clear record of the delay.
Knox does not patch your software. Remediating GitLab Community Edition and Enterprise Edition is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to own. Managing your compliance posture while you do it is not something you have to handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. For a case like CVE-2026-85706, exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-85706 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing it out now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid footing.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








