EUVD Vulnerability Catalog Actively Exploited (KEV)

EUVD-2026-76779

Severity: CRITICAL Base Score: 10 CVSS Version: 3.1

Vulnerability Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Scope (S): Changed
▪ Confidentiality Impact (C): High
▪ Integrity Impact (I): High
▪ Availability Impact (A): None

Affected Vendors & Systems

Vendor GitLab

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

GitLab

EPSS Probability

11.96

Known Aliases
GHSA-f47w-mrg9-g9p2 CVE-2026-85706
Published On

2026-09-12

Last Updated

2026-09-12

Exploited Since

2026-09-11