# CVE-2026-0723

## Summary

- **CVE ID:** CVE-2026-0723
- **Severity:** HIGH
- **CVSS Score:** 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-252
- **Published:** Jan 22, 2026
- **Last Modified:** Mar 12, 2026

## Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

## Affected Products

- GitLab — GitLab (18.6)
- GitLab — GitLab (18.7)
- GitLab — GitLab (18.8)

## References

- [CNA](https://gitlab.com/gitlab-org/gitlab/-/issues/585333)
- [CNA](https://hackerone.com/reports/3476052)
- [CNA](https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.85%
- **EPSS Percentile:** 55.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._