
Eclipse Foundation GitLab incident postmortem: CVE-2026-85706
Between 12 and 14 September 2026, our GitLab instance was affected by CVE-2026-85706, a critical vulnerability in GitLab that allowed unauthenticated attackers to read files from the server. Some of those files contained sensitive credentials, and they were copied by attackers before we closed the hole. The vulnerability is now fully remediated, the exposure is contained, and our investigation is complete.
We owe the community a clear account of what happened, what we’ve done about it, and what (if anything) you need to do. This is that account.
