CVE-2026-2745: Authentication Bypass Using an Alternate Path or Channel in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-2745?
CVE-2026-2745 has a high severity due to its potential to allow unauthorized access through bypassing WebAuthn two-factor authentication.
How do I fix CVE-2026-2745?
To remediate CVE-2026-2745, upgrade GitLab to version 18.8.7, 18.9.3, or 18.10.1.
Which versions of GitLab are affected by CVE-2026-2745?
CVE-2026-2745 affects all GitLab versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1.
What type of issue is CVE-2026-2745?
CVE-2026-2745 is an improper access control vulnerability impacting the two-factor authentication mechanism in GitLab.
How can CVE-2026-2745 affect users?
CVE-2026-2745 can allow unauthenticated users to bypass WebAuthn two-factor authentication, potentially compromising account security.