{"id":6040,"date":"2026-10-01T09:07:39","date_gmt":"2026-10-01T14:07:39","guid":{"rendered":"https:\/\/cert.pa\/?p=6040"},"modified":"2026-10-01T09:07:41","modified_gmt":"2026-10-01T14:07:41","slug":"csirt-panama-aviso-2026-sep-30-vulnerabilidad-critica-en-gitlab-ce-ee-que-permite-omitir-la-autenticacion-y-leer-archivos-del-servidor-cve-2026-85706","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=6040","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2026-sep-30: Vulnerabilidad Cr\u00edtica en GitLab CE\/EE que permite omitir la autenticaci\u00f3n y leer archivos del servidor \u2014 CVE-2026-85706"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Fecha de emisi\u00f3n:<\/strong> 30 de septiembre de 2026<br><strong>CVE ID:<\/strong> CVE-2026-85706<br><strong>Severidad:<\/strong> CR\u00cdTICA \u2014 CVSS 3.1: 10.0<br><strong>Vector CVSS:<\/strong> CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:N<br><strong>Tipo de vulnerabilidad:<\/strong> CWE-22: Recorrido de directorios (path traversal)<br><strong>Producto afectado:<\/strong> GitLab Community Edition (CE) y Enterprise Edition (EE), autogestionado<br><strong>Explotaci\u00f3n activa:<\/strong> S\u00ed \u2014 Reportada por GitLab y CERT-FR; seg\u00fan GitLab, incluida en el cat\u00e1logo CISA KEV desde el 11 de septiembre de 2026<br><strong>Fuente:<\/strong> NVD \/ GitLab \/ CERT-FR \/ CISA<br><strong>Clasificaci\u00f3n TLP:<\/strong> TLP:CLEAR (Difusi\u00f3n p\u00fablica)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I. Descripci\u00f3n<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Se ha identificado una vulnerabilidad de recorrido de directorios (path traversal) en GitLab CE\/EE, registrada como CVE-2026-85706 y calificada con 10.0 de 10 en la escala CVSS 3.1. Un atacante no autenticado podr\u00eda omitir la autenticaci\u00f3n y leer archivos arbitrarios del servidor a trav\u00e9s de la API de commits de repositorios, incluidos archivos de configuraci\u00f3n que contienen credenciales y secretos.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitLab y CERT-FR reportan que la vulnerabilidad ya est\u00e1 siendo explotada. El modelo EPSS estima en 91 % la probabilidad de que sea explotada en los pr\u00f3ximos 30 d\u00edas.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Descripci\u00f3n t\u00e9cnica publicada en NVD (en ingl\u00e9s): \u00abGitLab has remediated an issue in GitLab CE\/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.\u00bb<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>II. Productos Afectados<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Producto<\/th><th class=\"has-text-align-left\" data-align=\"left\">Versiones afectadas<\/th><th class=\"has-text-align-left\" data-align=\"left\">Versi\u00f3n corregida<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">GitLab CE\/EE<\/td><td class=\"has-text-align-left\" data-align=\"left\">18.7.0 \u2013 anteriores a 18.11.12<\/td><td class=\"has-text-align-left\" data-align=\"left\">18.11.12 o superior<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">GitLab CE\/EE<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.0.0 \u2013 anteriores a 19.0.9<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.0.9 o superior<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">GitLab CE\/EE<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.1.0 \u2013 anteriores a 19.1.8<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.1.8 o superior<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">GitLab CE\/EE<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.2.0 \u2013 anteriores a 19.2.6<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.2.6 o superior<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">GitLab CE\/EE<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.3.0 \u2013 anteriores a 19.3.2<\/td><td class=\"has-text-align-left\" data-align=\"left\">19.3.2 o superior<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>III. Acciones Requeridas<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Actualizar inmediatamente<\/strong><br>Actualizar GitLab CE\/EE a la versi\u00f3n 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 o superior, seg\u00fan la rama instalada.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Mitigar inmediatamente si no es posible parchear<\/strong><br>Mientras se realiza la actualizaci\u00f3n, restringir el acceso desde Internet a la interfaz o servicio afectado, permitiendo \u00fanicamente las direcciones de confianza que lo necesiten, y aplicar las mitigaciones indicadas por el fabricante.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Verificar posible compromiso<\/strong><br>El parche cierra el vector de explotaci\u00f3n, pero no elimina un acceso que el atacante ya haya obtenido. GitLab public\u00f3 tres reglas de detecci\u00f3n de amenazas para identificar intentos de explotaci\u00f3n en instancias autogestionadas:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00abGitLab LFI attempt reading gitlab.yml\u00bb \u2014 intentos de leer el archivo de configuraci\u00f3n gitlab.yml.<\/li>\n\n\n\n<li>\u00abGitLab LFI via metadata.path parameter\u00bb \u2014 lectura de archivos mediante el par\u00e1metro metadata.path.<\/li>\n\n\n\n<li>\u00abGitLab LFI file path attempt\u00bb \u2014 intentos de enumeraci\u00f3n de rutas de archivos.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Revisar los registros de acceso de GitLab (NGINX y Rails) en busca de solicitudes no autenticadas a la API de commits de repositorios con secuencias de recorrido de directorios (..\/ o sus variantes codificadas) desde antes de la actualizaci\u00f3n. Si se detecta explotaci\u00f3n, considerar comprometidos los secretos del servidor (gitlab.yml, gitlab-secrets.json, credenciales de base de datos, tokens y claves) y rotarlos.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reportar cualquier hallazgo a incidentes@cert.pa.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>IV. Referencias<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>National Institute of Standards and Technology (NIST). National Vulnerability Database: CVE-2026-85706. <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-85706\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-85706<\/a><\/li>\n\n\n\n<li>CISA. Known Exploited Vulnerabilities Catalog: CVE-2026-85706. <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706\">https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706<\/a><\/li>\n\n\n\n<li>GitLab. Patch Release: GitLab 19.0.9 released. <a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-0-9-released\/\">https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-0-9-released\/<\/a><\/li>\n\n\n\n<li>CERT-FR. Multiples vuln\u00e9rabilit\u00e9s dans GitLab (CERTFR-2026-AVI-1242). <a href=\"https:\/\/www.cert.ssi.gouv.fr\/avis\/CERTFR-2026-AVI-1242\/\">https:\/\/www.cert.ssi.gouv.fr\/avis\/CERTFR-2026-AVI-1242\/<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>V. Informaci\u00f3n de Contacto<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CSIRT PANAM\u00c1 \u00b7 Computer Security Incident Response Team<br>Autoridad Nacional para la Innovaci\u00f3n Gubernamental<br>E-Mail: incidentes@cert.pa \u00b7 info@cert.pa<br>Tel\u00e9fono: +507 520-CERT (2378) \u00b7 Web: https:\/\/cert.pa \u00b7 X: @CSIRTPanama \u00b7 Key ID: 16F2B124<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fecha de emisi\u00f3n: 30 de septiembre de 2026CVE ID: CVE-2026-85706Severidad: CR\u00cdTICA \u2014 CVSS 3.1: 10.0Vector CVSS: CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:NTipo de vulnerabilidad: CWE-22: [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":6038,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[72,246,144,68],"class_list":["post-6040","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad","tag-avisos-de-seguridad","tag-critico","tag-gitlab","tag-vulnerabilidades","severidad-critico"],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/6040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6040"}],"version-history":[{"count":1,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/6040\/revisions"}],"predecessor-version":[{"id":6042,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/6040\/revisions\/6042"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/6038"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}