
TRC analysis shows attackers exploited CVE-2024-9164, a CVSS 8.8 path traversal flaw in GitLab's commits API to read arbitrary server files without authentication. Within hours, they escalated privileges using stolen credentials from config files and moved laterally across CI/CD environments. Runtime segmentation helps limit blast radius when DevOps platforms are compromised. #CloudSecurity #DevSecOps 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/gitlab-cve-2026-85706-cvss-10-file-read-flaw-draws-in-wild-probes
Post summary
The excerpt reports that CVE-2024-9164, a path traversal flaw in GitLab’s commits API, has been actively exploited to read server files, elevate privileges using stolen config credentials, and move laterally across CI/CD environments, with no patch or PoC details provided.
