Corrective updates have been released for the collaborative development platform GitLab — 18.8.2, 18.7.2, 18.6.4, which fix a vulnerability (CVE-2026-0723) that allows bypassing the two-factor authentication check. To carry out an attack, the attacker must know the victim's credential identifier. The vulnerability is caused by a lack of proper validation of the return value in the authentication services.
Additionally, the new versions fix four more vulnerabilities, two of which are classified as critical. These issues lead to denial of service when specially crafted requests are sent to the Jira Connect integration component (CVE-2025-13927), release management API (CVE-2025-13928), and SSH (CVE-2026-1102), as well as to a looping issue when creating a specially crafted Wiki document (CVE-2025-13335).
All users are strongly advised to urgently install the update. Details of the issue are currently undisclosed and will be made publicly available 30 days after the patch is published. Information about the vulnerabilities has been reported to GitLab as part of an ongoing HackerOne bug bounty program.
Source: opennet.ru
