CVE-2026-0723Disclosure(gitlab / gitlab)

MEDIUMCVSS 7.4 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-252

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-04: 1Mentions · 2026-04-23: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-23: 104-0404-23
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-041
Disclosure1
2026-04-231
Patch1
Full discourse2 posts
  • Stack Shield@stackshield
    Patch

    GitLab's 2FA was bypassable for 3 weeks in January. If you self-host GitLab and didn't patch CVE-2026-0723, attackers could authenticate with just a password. https://stackshield.io/blog/gitlab-2fa-bypass-cve-2026-0723

    Post summary

    The tweet warns that GitLab’s CVE-2026-0723 2FA bypass was actively exploited in January; patching is required to prevent attackers from authenticating with just a password.

    0000040
  • Stack Shield@stackshield
    Disclosure

    A GitLab 2FA bypass (CVE-2026-0723) was just disclosed. If you're self-hosting GitLab, this one matters. Here's what happened and what to do. https://stackshield.io/blog/gitlab-2fa-bypass-cve-2026-0723 #CyberSecurity

    Post summary

    The post announces the discovery of a new GitLab 2FA bypass vulnerability (CVE-2026-0723) and suggests remediation steps, but offers no PoC, exploit details, or active exploitation evidence.

    0000043
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more