HIGH

CVE-2026-2745

Gitlab GitLab 2026-03-25 CVSS v3.1
CVSS
8.1

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.

Summary dbcve.org

GitLab CE/EE contains an authentication bypass vulnerability where inconsistent input validation in the WebAuthn two-factor authentication flow allows unauthenticated attackers to bypass 2FA and gain unauthorized access to user accounts.

Mitigation

Upgrade to GitLab versions 18.8.7, 18.9.3, or 18.10.1 or later. If immediate patching is not feasible, temporarily disable WebAuthn as a 2FA method and enforce alternative authentication factors.

Weakness (CWE)

CWE-288

EPSS Score

0.28%
Probability of exploitation in next 30 days
20.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE