Self-Managed GitLab File Read: Three Weeks On from CVE-2026-85706

Unauthenticated arbitrary file read on self-managed GitLab, still the right finding if the build is below the 10 and 23 September fixes. Not an appliance hunting guide.

PoCForge research card: self-managed GitLab file-read patch debt CVE-2026-85706
Unauthenticated arbitrary file read on self-managed GitLab, still the right finding if the build is below the 10 and 23 September fixes. Not an appliance hunting guide.
Three weeks is a long time for an unauthenticated file read. On 10 September 2026 GitLab shipped critical fixes in 19.3.2, 19.2.6 and 19.1.8, including CVE-2026-85706: an unauthenticated user could read arbitrary files on a self-managed GitLab server. On 23 September the same fix, and the fix for GraphQL CVE-2026-87719, was backported to 19.0.9 and 18.11.12. By 4 October 2026 a self-managed instance still below those builds is in the fourth week of a publicly documented, CISA KEV-listed issue. GitLab.com and GitLab Dedicated were already patched. This note is a version-and-secrets checklist, not a request recipe, and it is not an edge-appliance hunting guide.

PoCForge (Cyber Security) keeps this separate from AI-gateway work. CVE-2026-85706 is on the GitLab application’s repository commits API (CWE-22, improper path confinement, plus missing authentication). CVE-2026-90970 is a later, different component. Patching one does not close the other. Both are self-managed problems; neither is “GitLab.com will handle it” if you run the bits yourself.

1. Facts from the 10 September patch release

GitLab’s critical patch release states that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server because of improper path confinement and missing authentication enforcement in the repository commits API. CVSS 3.1 is 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). Availability is unchanged in that vector; confidentiality and integrity are high, and scope is changed. The CVE record matches the version ranges.

Line Affected Fixed build
18.7 up to but not including 18.11.12 Yes 18.11.12 (backport published 23 September 2026)
19.0 before 19.0.9 Yes 19.0.9 (same backport day)
19.1 before 19.1.8 Yes 19.1.8 (10 September 2026)
19.2 before 19.2.6 Yes 19.2.6
19.3 before 19.3.2 Yes 19.3.2
GitLab.com / Dedicated GitLab says already on the patched version No customer action for the managed platform

Builds before 18.7 are outside the range GitLab lists for CVE-2026-85706. That is not a reason to stay there: other issues in the same release notes reach much older floors, and an unsupported minor is its own finding. The 23 September update is what lets a self-managed admin on the 18.11 or 19.0 line take the fix without jumping all the way to 19.3. Waiting for a backport that has already shipped is no longer a status.

GitLab’s own release note says CVE-2026-85706 was added to CISA’s Known Exploited Vulnerabilities catalogue, and that GitLab published three detection rules for self-managed customers: an attempt aimed at the main configuration file, an attempt via the commits API path parameter, and a generic file-path attempt. Enable those rules if you run GitLab’s detection content. This article does not repeat request shapes. If the instance was internet-facing and unpatched after 10 September, treat readable files as exposed until you have evidence otherwise. Arbitrary file read, in GitLab’s words, includes whatever the server process can open: configuration and credentials live on that host.

Which line are you on?PoCForge / interactive
Backport line

Fixed at 18.11.12

18.7 up to but not including 18.11.12 is affected. The 23 September backport is 18.11.12. Builds before 18.7 are outside the range GitLab lists for this CVE, and an unsupported minor is still its own finding.

Backport line

Fixed at 19.0.9

19.0 before 19.0.9 is affected. The backport published on 23 September is 19.0.9.

10 September

Fixed at 19.1.8

19.1 before 19.1.8 is affected. Fixed build: 19.1.8.

10 September

Fixed at 19.2.6

19.2 before 19.2.6 is affected. Fixed build: 19.2.6.

10 September

Fixed at 19.3.2

19.3 before 19.3.2 is affected. Fixed build: 19.3.2, which includes post-deploy migrations. Plan downtime on single-node installs.

GitLab.com / Dedicated

No customer action on this CVE

GitLab says those platforms were already on the patched version. Self-managed omnibus, chart and source installs are the population this checklist is for.

Record the exact version and edition, including standby and disaster recovery. A chart pin is still a version.

2. CVE-2026-87719, accurately

The same patch trains fix a second critical issue, and only on Enterprise Edition. CVE-2026-87719 is insecure deserialisation in a GraphQL subscription serialiser (CWE-502). GitLab’s wording: under certain conditions an authenticated user with Duo Chat access could obtain Advanced Search instance configuration and sensitive credentials by using a crafted GraphQL subscription argument to bypass serialisation and look up a server object. CVSS 3.1 is 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Affected EE versions: 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

Do not file this as “the same bug as the file read”. Community Edition does not carry CVE-2026-87719. It requires an authenticated Duo Chat user, not an anonymous client. It is still in the same upgrade, so a self-managed EE that is late for CVE-2026-85706 is also late for this one. Duo Chat access is the population to review, the same way Duo Agent Platform access matters for the later gateway issue — related product surface, different CVE, different host.

The 10 September release also fixed a long list of high and medium issues (CI variable scope, Advanced Search indexing, package registry, SAML sign-in restriction, and others). A report that only names the CVSS 10 item understates why “we will take the next minor” is a weak plan. The action is still one upgrade to the fixed build for the line you are on, then a retest of version — not eighteen separate exploit exercises.

Edition splitterPoCForge / interactive
Edition splitterDo not file CVE-2026-87719 as the same bug as the file read. They share a fixed build. They do not share a population.COMMUNITYFile readENTERPRISEPlus GraphQLBOTH LATEOne upgrade
CVE-2026-85706

Unauthenticated file read on the application

Community Edition is in scope for CVE-2026-85706. It is not in the product list for CVE-2026-87719. The finding is version, exposure, and secret rotation. It is not an object-level authorisation write-up.

CVE-2026-87719

Duo Chat users, same upgrade

Enterprise Edition in the listed ranges is also late for insecure deserialisation in a GraphQL subscription serialiser. It needs an authenticated Duo Chat user, not an anonymous client. CVSS 3.1 is 9.9. Review who has Duo Chat; close it with the same fixed builds.

Do not split the change

Eighteen exercises are the wrong plan

The 10 September release also fixed a long list of high and medium issues. The action is one upgrade to the fixed build for the line you are on, then a retest of version — not a separate exercise per CVE.

Do not file CVE-2026-87719 as the same bug as the file read. They share a fixed build. They do not share a population.

3. What “three weeks on” should change in the test

Patch-debt clockPoCForge / interactive
Patch-debt clockSelf-managed only. Dates are disclosure and backport milestones, not an intrusion timeline.10 SEP19.1 / 19.2 / 19.3KEVGitLab confirmed23 SEP18.11 and 19.02 OCTGateway, other hostSTILL LATEIf below the fix
First fixed builds

19.3.2, 19.2.6 and 19.1.8

GitLab’s critical patch release fixes CVE-2026-85706 on those three lines. GitLab.com and GitLab Dedicated were already patched. A self-managed build below the fixed level on its line stays in scope.

Known exploited

GitLab says the CVE is in CISA’s catalogue

Treat an internet-facing, unpatched instance after 10 September as an assume-breach question for files the GitLab process could open. GitLab published three detection rules. Enable them if you run GitLab’s detection content. This note does not repeat request shapes.

Backports

18.11.12 and 19.0.9

The same fix, and the fix for GraphQL CVE-2026-87719, was backported. Waiting for a backport that has already shipped is no longer a status. “18.11” without the patch level is still affected.

Separate asset

The AI Gateway is not this CVE

CVE-2026-90970 is the self-hosted AI Gateway, patched on its own tags. Application 19.3.2 does not imply gateway 19.4.1. Track them as two patch debts.

This checklist

Upgrade closes the hole. It does not rotate secrets.

If the instance was reachable and below the fixed build at any point after disclosure, assume breach for data the GitLab OS user could read, plus the Enterprise Edition GraphQL issue if Duo Chat users exist. Upgrading does not answer whether a session token or a runner credential lived in a file the process could open.

Self-managed only. Dates are disclosure and backport milestones, not an intrusion timeline.

Authorised objectives:

  1. Classify each instance: GitLab.com or Dedicated (no action on this CVE), self-managed omnibus, chart, or source. “We use GitLab” is not a version.
  2. Record the exact version and edition. Map it onto the table above. A helm chart that pins an old application tag is still old.
  3. If it was internet-facing while affected, preserve access logs you already have and turn on GitLab’s published detections. Do not generate exploit traffic to “see if logging works”.
  4. List secrets that sit in files on that server: database credentials, runner tokens, SSO client secrets, cloud keys used by backups, Advanced Search credentials on EE. Rotate what you cannot prove was unreadable. Prefer rotation over a debate about whether a particular path was requested.
  5. For EE, list who has Duo Chat. CVE-2026-87719 is their issue, fixed by the same builds.
  6. Schedule the upgrade with eyes open: GitLab warns this patch includes database migrations, with downtime on single-node installs unless you are doing a proper zero-downtime multi-node upgrade. 19.3.2 includes post-deploy migrations. That is an operations fact, not a reason to skip the patch.
  7. Retest by version and by a clean unauthenticated probe that should now fail closed — a normal login-page and API authentication check, not a file-read payload.
  8. Separately record the AI Gateway image if you self-host it. See the gateway note. Application 19.3.2 does not imply gateway 19.4.1.
Defender checklistPoCForge / interactive

CVE-2026-85706 / CVE-2026-87719









0 checked

Ticks stay in this browser. They are not written back to the engagement file.

4. How to write the finding

Lead with exposure and version, then with secret rotation, then with the EE GraphQL population if it applies. CVSS 10 explains priority. It does not replace evidence. A useful finding names the host, the build, the date it was still vulnerable, whether it was reachable without SSO in front, and which credential classes were rotated. A weak finding pastes the advisory and stops.

Integrity in the CVSS vector is a reminder that “file read” is not only confidentiality: GitLab scored integrity high as well. Do not over-interpret that into a specific write primitive this note does not document. Do treat the host as untrusted until patched and until credentials that lived on it have been replaced.

This is application patch debt on the system that stores your source and CI variables. Pair it with API authorisation chains only if you are testing GitLab’s API as a product boundary in the same engagement — the unauthenticated file read is not an object-level authorisation bug, and forcing that frame hides the version problem. Cloud identity work (IAM attack paths) matters afterwards: keys read from the server become cloud principals. That sequence is why rotation is in the checklist.

Sources

Frequently asked questions

Does CVE-2026-85706 affect GitLab.com?

GitLab says GitLab.com was already running the patched version and GitLab Dedicated customers do not need to act. Self-managed CE and EE in the listed ranges do.

Is CVE-2026-87719 the same issue?

No. It is a separate critical fix in the same releases, Enterprise Edition only. An authenticated user with Duo Chat access could obtain Advanced Search configuration and sensitive credentials via a GraphQL subscription argument. Community Edition is not in that CVE’s product list. Both are closed by the same fixed builds.

We are on 18.11. Is the backport enough?

GitLab’s 23 September update says self-managed admins on older lines can take 18.11.12 or 19.0.9 for CVE-2026-85706 and CVE-2026-87719. Confirm you actually reached those builds. “18.11” without the patch level is still in the affected range.

Is patching enough if we were exposed?

Patching stops the unauthenticated read. It does not invalidate credentials that were already in files the server could open, and GitLab has said the issue is in CISA’s KEV catalogue. Rotate secret material you cannot prove stayed unread, keep the logs you have, and enable the vendor’s detection rules. Do not run a proof of concept against production to answer the question.