{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-7CE1D780",
  "slug": "cve-2026-85706-gitlab-commits-api-path-traversal-kev",
  "title": "GitLab unauth commits API file read (CISA KEV)",
  "aliases": [
    "CVE-2026-85706",
    "GitLab commits API path traversal"
  ],
  "summary": "Self-managed GitLab CE/EE in affected 18.7–19.3 trains had improper path confinement on the commits API so that, under certain conditions, an unauthenticated user could read arbitrary files from the GitLab server. CISA added it to KEV. Upgrade to 19.1.8, 19.2.6, or 19.3.2.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Exact trigger conditions are described in GitLab's advisory; confirm your minor train before choosing 19.1.8 vs 19.2.6 vs 19.3.2.",
  "firstObservedAt": "2026-09-11T00:00:00.000Z",
  "lastObservedAt": "2026-09-11T20:17:19.396Z",
  "publishedAt": "2026-09-20T18:52:58.756Z",
  "reviewedAt": "2026-09-20T18:52:48.348Z",
  "expiresAt": "2026-09-11T20:17:19.396Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "gitlab-wi",
      "label": "GitLab work item 627748",
      "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/627748",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-11T20:17:19.396Z"
    },
    {
      "id": "cisa-kev",
      "label": "CISA KEV catalog entry",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706",
      "sourceType": "government",
      "observedAt": "2026-09-11T20:17:19.396Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-85706",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-11T20:17:19.396Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-85706-gitlab-commits-api-path-traversal-kev",
      "sourceType": "other_primary",
      "observedAt": "2026-09-11T20:17:19.396Z"
    }
  ],
  "artifacts": [
    {
      "id": "gitlab-ce-ee",
      "artifactClass": "package",
      "ecosystem": "gitlab",
      "name": "GitLab CE/EE",
      "version": ">=18.7 <19.1.8 || >=19.2 <19.2.6 || >=19.3 <19.3.2",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-11T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "GitLab remediated CVE-2026-85706 for commits API path traversal on self-managed instances.",
      "sourceIds": [
        "gitlab-wi",
        "nvd"
      ]
    },
    {
      "id": "kev",
      "occurredAt": "2026-09-11T00:00:00.000Z",
      "eventType": "other",
      "summary": "CISA listed CVE-2026-85706 in the Known Exploited Vulnerabilities catalog.",
      "sourceIds": [
        "cisa-kev"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-11T20:17:19.396Z",
      "eventType": "other",
      "summary": "HOL Guard published operator blog coverage noting CISA KEV.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Affects GitLab CE/EE from 18.7 before the listed fixed minors.",
    "CISA KEV listing elevates urgency; this campaign does not invent exploit tooling details.",
    "Path traversal file read is the scoped impact — not claimed RCE unless a separate advisory says so."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-85706-gitlab-commits-api-path-traversal-kev/corrections"
}
