• News/
  • https://www.bleepingcomputer.com/news/security/gitlab-warns-of-high-severity-2fa-bypass-denial-of-service-flaws/

GitLab warns of high-severity 2FA bypass, denial-of-service flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 21, 2026
·
Updated

GitLab has patched a high-severity two-factor authentication bypass impacting community and enterprise editions of its software development platform. Tracked as CVE-2026-0723, this vulnerability stems from an unchecked return value weakness in GitLab's authentication services, allowing attackers who know the target's account ID to circumvent two-factor authentication. "GitLab has remediated an issue that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses," the company explained. GitLab also addressed two high-severity flaws affecting GitLab CE/EE that could enable unauthenticated threat actors to trigger denial-of-service (DoS) conditions by sending crafted requests with malformed authentication data (CVE-2025-13927) and exploiting incorrect authorization validation in API endpoints (CVE-2025-13928). Additionally, it patched two medium-severity DoS vulnerabilities that can be exploited by configuring malformed Wiki documents that bypass cycle detection (CVE-2025-13335) and sending repeated malformed SSH authentication requests (CVE-2026-1102). To address these security flaws, the company has released versions 18.8.2, 18.7.2, and 18.6.4 for GitLab Community Edition (CE) and Enterprise Edition (EE), and has advised admins to upgrade to the latest version as soon as possible. "These versions contain important bug and security fixes, and we strongly recommend that all self...

Read full article

Affected Software

6 affected components
GitLab Community Edition=18.8.2
GitLab Community Edition=18.7.2
GitLab Community Edition=18.6.4
GitLab Enterprise Edition=18.8.2
GitLab Enterprise Edition=18.7.2
GitLab Enterprise Edition=18.6.4
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main security issue reported in this article?

The article discusses a high-severity two-factor authentication bypass vulnerability in GitLab.

2

What are the potential consequences of the reported vulnerabilities?

The vulnerabilities could allow attackers to bypass two-factor authentication and potentially execute denial-of-service attacks.

3

Which versions of GitLab are affected by the identified vulnerabilities?

The affected versions include GitLab Community Edition and Enterprise Edition versions 18.6.4, 18.7.2, and 18.8.2.

4

Who is responsible for fixing the security vulnerabilities mentioned?

GitLab has issued patches to address the vulnerabilities in their software.

5

What is the identifier assigned to the two-factor authentication bypass vulnerability?

The vulnerability is tracked as CVE-2026-0723.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203