SECURITY·중요도 10·2026. 09. 11.·The Hacker News
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
── KO ──────────────────
GitLab의 CVSS 10 보안 취약점이 공개 직후 실시간 공격에 노출됐다.
GitLab은 여러 가지 결함을 해결하기 위한 패치를 릴리스했다. 그 중 최대 심각도인 CVE-2026-85706 취약점은 경로 탐색 문제로, 인증되지 않은 사용자가 GitLab 서버에서 임의 파일을 읽을 수 있는 가능성이 있다. 이 결함은 공개 후 몇 시간 이내에 실제 공격을 받았다.
── EN ──────────────────
GitLab's CVSS 10 vulnerability exposed to in-the-wild probes right after disclosure.
GitLab has released patches addressing several vulnerabilities, including a maximum-severity issue identified as CVE-2026-85706. This vulnerability is a path traversal flaw that might allow unauthenticated users to read arbitrary files from the GitLab server. The flaw was probed in-the-wild mere hours after it was made public.