HomeSecurityGitLab: Vulnerability allows bypass of 2FA protection

GitLab: Vulnerability allows bypass of 2FA protection

A critical vulnerability that allows bypassing two-factor authentication (2FA) in the Community and Enterprise of GitLab needs to be patched immediately, according to experts. The flaw is one of five that were patched on Wednesday as part of new GitLab releases. Three of the vulnerabilities are rated high severity, including the 2FA bypass issue, while the other two are rated medium severity.

GitLab

GitLab reports that the 2FA flaw, CVE-2026-0723, could allow an individual, with knowledge of the victim's ID credentials, to bypass two-factor authentication by submitting fake device responses.

See also: Binary-parser bug allows code execution in Node.js

This gap has caught the attention of experts because of its implications. The goal of multi-factor authentication is to protect accounts with an extra step of verification in case usernames and passwords are stolen. If a malicious user can gain access to an account, they can cause almost unlimited damage to IT systems.

GitLab 2FA Bypass: Implications

In the case of GitLab, if critical code is in a developer's account, a malicious user could compromise it. If that code is going to be used in software that can be downloaded or sold to other organizations, then the imported malware could be spread in a supply chain attack.

The most recent example is the Shai-Hulud worm, which spreads because a developer account in the npm registry was compromised. If the code contains cloud secrets, the malicious user can gain access to cloud platforms such as Azure, Amazon Web Service, or Google Cloud Platform.

GitLab: Vulnerability allows bypass of 2FA protection

The discovery of the 2FA bypass loophole is a reminder that security checks are important.

This is not the first time we've heard of 2FA bypass attacks. There are various methods that have been used for this purpose.

See also: Vulnerabilities in Chainlit AI: Risk to servers

Once the attacker has access to valid passwords, they can connect to the GitLab server and perform actions on the source code — download it, modify it, or delete it — just as a legitimate user would.

What infosec leaders should do

That's why Cybersecurity 101 — layered defense — is crucial for identity and access management, according to experts.

This type of defense requires employees to have long, unique passwords and requires monitoring the network for unusual activity (for example, if someone logs in without registering an MFA challenge). If all else fails, there should be an incident response plan.

The expert warns that MFA bypass vulnerabilities are very common. “The underlying problem is usually that MFA was added later to an existing product and some features may not properly check whether MFA was successfully completed.” When testing a multi-factor authentication solution, information security leaders should always verify that an application has not marked the authentication as complete after verifying the username and password.

See also: Advanced Custom Fields: Extended WordPress – Serious vulnerability

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, enabling MFA should not relax password requirements. Users should still choose unique, strong passwords and use password managers to manage them. Strong passwords will mitigate any MFA failures.

GitLab: Vulnerability allows bypass of 2FA protection

Vulnerabilities in GitLab are significant

GitLab is typically used by organizations that are concerned enough about the confidentiality of their code to want to run the platform on-premises.

Describing the fixes released Wednesday, GitLab said it “strongly recommends” upgrading all self-managed GitLab installations to one of three new releases (18.8.2, 18.7.2, 18.6.4) for GitLab Community Edition (CE) and Enterprise Edition (EE). Those using GitLab.com or GitLab Dedicated — a single-tenant software-as-a-service version — don’t need to take any action.

The other vulnerabilities fixed in Wednesday's updates are:

CVE-2025-13927, a denial of service in the Jira Connect integration.

CVE-2025-13928, an incorrect authorization issue.

CVE-2025-13335, an infinite loop issue in Wiki redirects.

CVE-2026-1102, a denial of service issue in an API endpoint.

As per standard GitLab practice, details of security vulnerabilities will be made public on an issue tracker 30 days after the fixes are released.

New releases also include bug fixes and some may include database migrations. In the case of single-node instances, a fix will cause downtime during the upgrade. In the case of multi-node instances, administrators who follow the correct zero-downtime upgrade procedures can apply a fix without downtime.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS