
GitLab's 2FA was bypassable for 3 weeks in January. If you self-host GitLab and didn't patch CVE-2026-0723, attackers could authenticate with just a password. https://stackshield.io/blog/gitlab-2fa-bypass-cve-2026-0723
Post summary
The tweet warns that GitLab’s CVE-2026-0723 2FA bypass was actively exploited in January; patching is required to prevent attackers from authenticating with just a password.
