GitLab exploit leaves no traversal string says Black Hills Information Systems

Black Hills Information Security has just published new research, “The GitLab Exploit With No Traversal In It,” showing that detection guidance circulating for the recently exploited GitLab vulnerability, CVE-2026-85706, may send security teams looking for the wrong indicators.

The critical vulnerability allows unauthenticated attackers to read arbitrary files from affected GitLab servers under certain conditions. CISA lists it as exploited in the wild, making the question of how to detect exploitation immediately relevant.

Black Hills’ Active SOC team examined nginx and Rails logs and tested Sigma and Suricata detection rules. Its research challenges reliance on commits-endpoint monitoring alone and gives security teams practical guidance for investigating suspicious activity. The testing described in “The GitLab Exploit With No Traversal In It” is controlled validation, it’s not a count of attacks observed against customers.

Eric Capuano, Black Hills Information Security’s Director of SOC Operations, notes that for enterprises, the concern extends beyond the initial file read: exposed credentials or secrets could enable further compromise. Patches are available in GitLab versions 19.1.8, 19.2.6, and 19.3.2. Updating closes the vulnerability, but does not establish whether sensitive information was accessed beforehand.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading