GitLab Alert: High-Severity 2FA Bypass & DoS Flaws Patched in Urgent Update
ID: e7c826dc-e713-5ca8-b865-2ca08fd89c7c
STIX ID: report--e7c826dc-e713-5ca8-b865-2ca08fd89c7c
Feed Name: securityonline.info
GitLab released an urgent security update for Community and Enterprise editions (target versions 18.8.2, 18.7.2, 18.6.4) fixing five high-severity CVEs — notably CVE-2026-0723, a CVSS 7.4 two-factor authentication bypass that could allow account takeover with knowledge of a credential ID, and multiple denial-of-service flaws affecting APIs, Jira Connect, Wiki handling, and SSH requests; administrators are strongly urged to upgrade immediately to mitigate potential account compromises and instance crashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
