CVE-2026-85706 is a critical vulnerability (CVSS 10.0) in GitLab that allows unauthenticated attackers to read arbitrary files from the server by URL-encoding a single character in API requests, bypassing authentication entirely. The flaw has been exploited in the wild and is tracked in CISA's KEV catalog. Self-hosted GitLab installations must update to versions 19.1.8, 19.2.6, or 19.3.2 immediately.