logo

Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks

ID: 884ebce2-7c80-57d1-bbbf-bc53ea1182b7

STIX ID: report--884ebce2-7c80-57d1-bbbf-bc53ea1182b7

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Abinaya

...
...

GitLab released critical patches for multiple vulnerabilities across versions 18.6–18.8 (and other ranges) affecting both Community and Enterprise editions. The most severe is CVE-2026-0723, an unchecked return value in authentication that permits 2FA bypass via forged device responses; additional high-severity issues include DoS and incorrect authorization flaws (CVE-2025-13927, CVE-2025-13928). Administrators of self-managed instances are urged to apply updates immediately (GitLab.com and Dedicated customers are already protected) and follow post-deploy migration guidance to avoid downtime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.