#VU124602 Improper Access Control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-2745
Published: March 25, 2026 / Updated: March 25, 2026
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts.
The vulnerability exists due to inconsistent input validation in the WebAuthn 2FA authentication process when handling requests. A remote user can send a specially crafted authentication request to bypass two-factor authentication and gain unauthorized access to user accounts.