# CVE-2023-7028

## Summary

- **CVE ID:** CVE-2023-7028
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
- **CWE:** CWE-640
- **Published:** Jan 12, 2024
- **Last Modified:** Aug 15, 2026

## Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

## Affected Products

- GitLab — GitLab (16.1)
- GitLab — GitLab (16.2)
- GitLab — GitLab (16.3)
- GitLab — GitLab (16.4)
- GitLab — GitLab (16.5)
- GitLab — GitLab (16.6)
- GitLab — GitLab (16.7)

## References

- [CNA](https://gitlab.com/gitlab-org/gitlab/-/issues/436084)
- [CNA](https://hackerone.com/reports/2293343)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7028)
- [CVE](https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 93.38%
- **EPSS Percentile:** 99.8

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** May 1, 2024
- **Due Date:** May 22, 2024

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._