CVE-2026-2745
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.
Summary dbcve.org
GitLab CE/EE contains an authentication bypass vulnerability where inconsistent input validation in the WebAuthn two-factor authentication flow allows unauthenticated attackers to bypass 2FA and gain unauthorized access to user accounts.
Mitigation
Upgrade to GitLab versions 18.8.7, 18.9.3, or 18.10.1 or later. If immediate patching is not feasible, temporarily disable WebAuthn as a 2FA method and enforce alternative authentication factors.