logo

GitLab Alert: High-Severity 2FA Bypass & DoS Flaws Patched in Urgent Update

ID: e7c826dc-e713-5ca8-b865-2ca08fd89c7c

STIX ID: report--e7c826dc-e713-5ca8-b865-2ca08fd89c7c

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-01-21

Date Updated: 2026-04-23

Author: Ddos

...
...

GitLab released an urgent security update for Community and Enterprise editions (target versions 18.8.2, 18.7.2, 18.6.4) fixing five high-severity CVEs — notably CVE-2026-0723, a CVSS 7.4 two-factor authentication bypass that could allow account takeover with knowledge of a credential ID, and multiple denial-of-service flaws affecting APIs, Jira Connect, Wiki handling, and SSH requests; administrators are strongly urged to upgrade immediately to mitigate potential account compromises and instance crashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.