[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-29779":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":72,"vuln_id":94,"name":95,"published":96,"updated":96},29779,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":68,"name":71},"Sniper",{"id":65,"codename":73,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":79,"references":80,"cvssv3":83,"epss_score":84,"epss_percentile":85,"cve":86,"in_cisa_catalog":88,"date":89,"software_type":90,"vendor":91,"product":91,"ptt_exploit_capabilities":92},null,"We found that the target server is vulnerable to CVE-2026-85706, an arbitrary file read vulnerability in the GitLab repository API that requires no authentication. GitLab Workhorse matches its interception rules against the escaped URL path, while Rails routes the decoded path. Percent-encoding a single character of a static route segment, such as \u003Ccode>\u002Fapi\u002Fv4\u002Fprojects\u002F1\u002Frepository\u002F%66iles\u002Fx\u003C\u002Fcode>, or simply appending a trailing slash, therefore makes Workhorse skip the request instead of rewriting it. The upload metadata that Workhorse normally generates is then accepted straight from the query string, and the Rails handler opens the local path given in \u003Ccode>file.path\u003C\u002Fcode> before any authentication check runs. We have detected this vulnerability by sending such a request with a \u003Ccode>file.path\u003C\u002Fcode> value pointing to a file that does not exist on the target, and confirming that the server reports the missing local file instead of rejecting the request as unauthenticated, then by reading a GitLab application source file from the server. The file is read with the privileges of the account that runs GitLab, and its content is returned inside the error raised while the server parses that content as form data.","critical","The risk exists that a remote unauthenticated attacker can read configuration files, application source code and log files from the GitLab server, and use the credentials, tokens and other confidential information they contain to further compromise the system.","GitLab is vulnerable to CVE-2026-85706, an arbitrary file read vulnerability in the repository API that requires no authentication. GitLab Workhorse and Rails disagree on how an encoded URL path is interpreted, so a request that percent-encodes one character of the route escapes the processing Workhorse normally performs. The upload metadata is then taken directly from the request, and the server opens the local file named by the attacker before verifying who is asking. This allows a remote unauthenticated attacker to read files belonging to the GitLab installation, such as configuration files, application source code and log files, with the privileges of the account that runs GitLab.","Update GitLab to version 19.3.2, 19.2.6 or 19.1.8, depending on the release series in use.","We recommend updating GitLab Community Edition or Enterprise Edition to version 19.3.2, 19.2.6 or 19.1.8, depending on the release series in use, since these are the versions in which this vulnerability was fixed.",[81,82],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-85706","https:\u002F\u002Fdocs.gitlab.com\u002Freleases\u002Fpatches\u002Fpatch-release-gitlab-19-3-2-released\u002F",10,0.92956,0.9983,[87],"CVE-2026-85706",true,"2026-09-10T00:00:00Z","DevOps Platform","GitLab",[93],"CUSTOM","NETSCAN-SNIPER-CVE-2026-85706","GitLab - Arbitrary File Read","2026-09-29T00:00:00Z"]