CVE-2026-26060: Fleet: Password reset tokens remain valid after password change for 24 hours
A vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, a stale password reset token could be reused to reset the account password even after a defensive password change.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-26060 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →