{"type":"bundle","id":"bundle--41b92133-5a30-59d4-a92e-50a3dafbaa64","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--6ec323df-cda4-55b5-96c2-50c3512ffe91","created":"2026-09-20T18:52:58.756Z","modified":"2026-09-20T18:52:58.756Z","name":"GitLab unauth commits API file read (CISA KEV)","description":"Self-managed GitLab CE/EE in affected 18.7–19.3 trains had improper path confinement on the commits API so that, under certain conditions, an unauthenticated user could read arbitrary files from the GitLab server. CISA added it to KEV. Upgrade to 19.1.8, 19.2.6, or 19.3.2.","aliases":["CVE-2026-85706","GitLab commits API path traversal"],"first_seen":"2026-09-11T00:00:00.000Z","last_seen":"2026-09-11T20:17:19.396Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"GitLab work item 627748","url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/627748"},{"source_name":"CISA KEV catalog entry","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706"},{"source_name":"NVD CVE-2026-85706","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85706"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-85706-gitlab-commits-api-path-traversal-kev"}]}]}