← Vulnerability feed

Vulnerability record · CVE-2023-7028 · published 12 January 2024

CVE-2023-7028: GitLab CE/EE password reset sent to unverified email, enabling account takeover

Gitlab · Gitlab

GitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. An attacker who controls or can add an unverified address on a target account can receive the reset link and take over that account. The flaw is a weak password recovery design (CWE-640) and carries a critical CVSS of 9.8.

9.8 CVSS 3.1 Critical CISA KEV since 1 May 2024 EPSS 95% · top 0.1% CWE-640 · Weak password recovery
9.8CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated, no-interaction account takeover with a 9.8 CVSS, KEV listing and near-maximum EPSS makes this an urgent patch-first item.

What it is

GitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. An attacker who controls or can add an unverified address on a target account can receive the reset link and take over that account. The flaw is a weak password recovery design (CWE-640) and carries a critical CVSS of 9.8.

Impact

An attacker gains full control of a targeted GitLab user account, including any repositories, tokens and permissions that account holds. Because the vector is unauthenticated and needs no user interaction, compromise can be automated at scale.

Attack surface

Reachable over the network through the GitLab password reset flow; the CVSS vector shows no privileges and no user interaction required. The reset email is simply directed to an unverified address, so the victim does not need to click anything.

Exploitation

CVE-2023-7028 is listed in CISA KEV with a 2024-05-22 remediation due date, and reference tags include Exploit and Third Party Advisory. EPSS is 0.94647 (99.851st percentile), indicating very high likelihood of exploitation activity.

What to do

  • Upgrade GitLab CE/EE to 16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4 or 16.7.2 (or later) as applicable to your track.
  • If immediate upgrade is not possible, follow the vendor's mitigation guidance referenced in the CISA KEV entry or discontinue use of the affected instance.
  • Enable and enforce two-factor authentication on all GitLab accounts to reduce the value of a stolen reset flow.
  • Audit account email addresses and remove or verify any unverified secondary addresses.
  • Restrict network exposure of GitLab instances to trusted networks until patched.

Detection

  • Review GitLab authentication logs for password reset requests and subsequent logins from new IPs or user agents.
  • Alert on password reset events where the destination email differs from the account's primary verified address.
  • Monitor for mass or scripted password reset requests across many accounts in a short window.
  • Correlate successful logins immediately following a password reset with anomalous source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-7028 to the Known Exploited Vulnerabilities catalog on 1 May 2024 as "GitLab Community and Enterprise Editions Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 22 May 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-7028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed10.0CVE-2021-22205GitLab CE/EE image parser flaw allows unauthenticated remote code executionGitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The fla…KEVEPSS 100%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed7.5CVE-2021-39935GitLab CI Lint API server-side request forgeryGitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 …KEVEPSS 36%analysed10.0CVE-2020-13300Gitlab incorrect authorization vulnerabilityGitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…EPSS 1.3%10.0CVE-2019-9174Gitlab server-side request forgery (ssrf) vulnerabilityAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.EPSS 2.0%10.0CVE-2018-18843Gitlab server-side request forgery (ssrf) vulnerabilityThe Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.EPSS 1.6%9.9CVE-2025-5121Gitlab missing authorization vulnerabilityAn issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check m…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2023-7028), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.