Sploitus

Exploit for CVE-2026-85706

kitploit Β· 2026-09-14

Exploit Code

MARKDOWN18 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-GABRIELUNKNOWN-CVE-2026-85706
# CVE-2026-85706 β€” GitLab Unauthenticated Arbitrary File Read

![CVSS](https://img.shields.io/badge/CVSS-10.0%20CRITICAL-red) ![GitLab](https://img.shields.io/badge/GitLab-CE/EE-orange) ![License](https://img.shields.io/badge/Use-Authorized%20Only-yellow) ![MITRE](https://img.shields.io/badge/MITRE-T1083%20%7C%20T1552.001-blue)

> **For authorized penetration testing and Red Team operations only.**  
>  Unauthorized use constitutes a criminal offense. See Legal Notice.

* * *

## Overview

**CVE-2026-85706** is a CVSS 10.0 path traversal vulnerability in GitLab Community and Enterprise Editions that allows a completely **unauthenticated attacker** to read **arbitrary files** from the server filesystem with a single HTTP request. No credentials, no token, no user interaction required.

  * **Disclosed:** September 10, 2026
  * **First exploitation observed:** September 11, 2026 (within 6 hours of disclosure)
  * **CISA KEV Added:** September 11, 2026
  * **Fixed in:** GitLab 19.1.8 / 19.2.6 / 19.3.2