Information about the Gitlab CVE-2026-85706 Path Traversal vulnerability

Information notice Main Services GitLab Managed Server and Services BURP Backup Infrastructure Package Cache

Updates

Information

Dear Customer,

We would like to update you on our status regarding the recently disclosed GitLab security vulnerability CVE-2026-85706 (path traversal).

We have taken the necessary measures and patched all our GitLab instances.

While our initial analysis of the logs shows attempted access via path traversal, there are no indications of a data breach or system compromise [1]. We are currently reviewing the system logs in detail once again, but as of now, we are confident that the security of your data has not been compromised.

As it is Best Practice, please be vigilant following such incidents. We ask that you notify us immediately if you notice any suspicious or unusual activity related to your GitLab projects.

If you notice anything unusual or have any questions, please contact us. Otherwise, we will inform as soon as our detailed analysis is complete or we have new findings, we will inform you immediately.

[1] https://gitlab.com/gitlab-security-oss/tldr/-/blob/main/Detections/platforms/GitLab/Vulnerability%20Detections/local_file_inclusion_path_enumeration.md?ref_type=heads

September 16, 2026 · 13:34 CEST

← Back