More

    GitLab patches major security flaw – here’s what we know



    • GitLab patched CVE-2026-0723, a flaw allowing 2FA bypass and account takeover
    • Additional DoS vulnerabilities in authentication, API endpoints, Wiki, and SSH were also fixed
    • GitLab urges immediate upgrades; ~6,000 exposed CE instances remain potential targets

    GitLab fixed a high-severity vulnerability in its Community Edition and Enterprise Edition (CE/EE) versions allowed threat actors to bypass two-factor authentication and potentially take over people’s accounts.

    “GitLab has remediated an issue that could have allowed an individual with existing knowledge of a victim’s credential ID to bypass two-factor authentication by submitting forged device responses,” the company said in a security advisory.


    https://cdn.mos.cms.futurecdn.net/gG5z7DmbnYVRrzM4o6XMzK-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img