216.73.217.22

CVE-2026-0723

· Published 22/01/2026 16:16 · Modified 28/01/2026 15:52 · Author: The MITRE Corporation

Labels: CVE-2026-0723 2026-01-22CVE-2026-0723CWE-252[email protected]

Essential information

Published
22/01/2026 16:16
Modified
28/01/2026 15:52
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
7.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:N

CVSS metrics

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:18.6.0-18.6.3:*:*:*:*:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:18.7.0-18.7.1:*:*:*:*:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:18.8.0-18.8.1:*:*:*:*:*:*:*

References