← Tutte le news
ARTICOLO
22 settembre 2026

GitLab CVE-2026-85706 KEV scaduta — scala patch e rotazione secret residua

BOZZA, solo difesa. CVE-2026-85706 KEV scaduta (due 14/09/2026). Upgrade 19.1.8/19.2.6/19.3.2+; rotazione secret residua; solo detection vendor. Niente path PoC.

GitLab self-managed: confermare la patch, poi cercare esposizione residua

CVE-2026-85706 è in CISA KEV (dateAdded 11/09/2026, due 14/09/2026, scaduta). Secondo il vendor: path traversal nell’API repository commits può consentire lettura arbitraria di file non autenticata. Aggiornare a 19.1.8 / 19.2.6 / 19.3.2+. GitLab.com e Dedicated sono già patchati.

Fonte: GitLab 19.3.2 patch release, 10/09/2026.

Estate MSP self-managed: confermare che l’istanza sia su una versione corretta, poi assumere che i secret su disco in path raggiungibili possano essere stati esposti prima della patch. Ruotare quelle credenziali, rivedere i log di accesso solo con regole di detection del vendor e chiudere la caccia residua con evidenze. Non inventare path exploit in ticket o runbook.

# MSP defensive checklist — GitLab CVE-2026-85706 — NO PoC paths
1. Confirm self-managed version is 19.1.8 / 19.2.6 / 19.3.2 or newer
2. Note GitLab.com and Dedicated are already patched per vendor
3. Inventory secrets that may have lived on reachable disk paths
4. Rotate those credentials and revoke stale tokens
5. Review access logs using vendor detection rules only
6. Close residual hunt with owner, evidence and exception expiry

Divieto: niente path exploit, PoC o passi di riproduzione. Solo bozza. Pubblica l’umano.