GitLab Community and Enterprise Editions Improper Access Control Vulnerability

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

Published 5 Sep 2026Updated 5 Sep 202621 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

Affected versions

GitLab CE/EE: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 51889GitLab CE/EE < 16.7.2 - Password Reset0xB4552024-03-14VerifiedPoC-in-GitHub · RandomRobbieBF/CVE-2023-7028CVE-2023-7028★ 58RandomRobbieBF2024-01-12CandidatePoC-in-GitHub · googlei1996/CVE-2023-7028CVE-2023-7028 poc★ 0googlei19962024-01-12CandidatePoC-in-GitHub · duy-31/CVE-2023-7028An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.★ 3duy-312024-01-12CandidatePoC-in-GitHub · Vozec/CVE-2023-7028This repository presents a proof-of-concept of CVE-2023-7028★ 245Vozec2024-01-12CandidatePoC-in-GitHub · yoryio/CVE-2023-7028Exploit for CVE-2023-7028 - GitLab CE/EE★ 0yoryio2024-01-18CandidatePoC-in-GitHub · Esonhugh/gitlab_honeypotCVE-2023-7028 killer★ 4Esonhugh2024-01-18CandidatePoC-in-GitHub · Shimon03/CVE-2023-7028-Account-Take-Over-Gitlab★ 0Shimon032024-01-23CandidatePoC-in-GitHub · thanhlam-attt/CVE-2023-7028★ 2thanhlam-attt2024-01-23CandidatePoC-in-GitHub · Trackflaw/CVE-2023-7028-DockerRepository to install CVE-2023-7028 vulnerable Gitlab instance★ 3Trackflaw2024-01-25CandidatePoC-in-GitHub · mochammadrafi/CVE-2023-7028Python Code for Exploit Automation CVE-2023-7028★ 0mochammadrafi2024-01-26CandidatePoC-in-GitHub · hackeremmen/gitlab-exploitGitLab CVE-2023-7028★ 1hackeremmen2024-01-28CandidatePoC-in-GitHub · soltanali0/CVE-2023-7028Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.★ 0soltanali02024-07-25CandidatePoC-in-GitHub · gh-ost00/CVE-2023-7028CVE-2023-7028 POC && Exploit★ 1gh-ost002024-08-21CandidatePoC-in-GitHub · sariamubeen/CVE-2023-7028★ 3sariamubeen2025-02-17CandidatePoC-in-GitHub · Sornphut/CVE-2023-7028-GitLab★ 0Sornphut2025-03-29CandidatePoC-in-GitHub · szybnev/CVE-2023-7028This FORK of repository presents a proof-of-concept of CVE-2023-7028. I am only improve exploit usage★ 1szybnev2025-07-21CandidatePoC-in-GitHub · KameliaZaman/Exploiting-GitLab-CVE-2023-7028Penetration test targeting CVE-2023-7028★ 0KameliaZaman2025-08-05CandidatePoC-in-GitHub · FearThePLOTO/GitLab-CVE-2023-7028A mock app for the GitLab CVE-2023-7028, which allow multile email adresses when ordering a password reset.★ 0FearThePLOTO2026-09-06Candidate