CVE-2026-4208: Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
(updated )
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-4208 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →