GitLab Fixes Major Security Flaws – Here’s What We Know


  • GitLab patched CVE-2026-0723, a bug that allows 2FA bypass and account takeover
  • Additional DoS vulnerabilities in authentication, API endpoints, Wiki and SSH were also fixed
  • GitLab encourages immediate upgrades; ~6,000 exposed CE instances remain potential targets

GitLab has fixed a serious vulnerability in their Community Edition and Enterprise Edition (CE/EE) versions that allowed threat actors to bypass two-factor authentication and potentially take over people’s accounts.

“GitLab has fixed an issue that could have allowed someone with existing knowledge of a victim’s credential ID to bypass two-factor authentication by submitting forged device responses,” the company said in a security advisory.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top