EUVD Vulnerability Catalog Actively Exploited (KEV)

EUVD-2026-76779

Severity: CRITICAL Base Score: 10 CVSS Version: 3.1

Vulnerability Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Changed
Confidentiality Impact (C): High
Integrity Impact (I): High
Availability Impact (A): None

Affected Vendors & Systems

Vendor GitLab

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

GitLab

EPSS Probability

0

Known Aliases
GHSA-f47w-mrg9-g9p2 CVE-2026-85706
Published On

2026-09-12

Last Updated

2026-09-12

Exploited Since

2026-09-11