Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement checks.
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

GitLab has a missing authentication enforcement check that can allow an authenticated user to bypass SAML SSO sign‑in restrictions and authenticate without SSO. The flaw is a direct application of CWE-306, where an application does not verify that a user is authenticated before allowing access to a protected function. This bypass could enable an attacker who already has legitimate credentials to obtain access to resources that are intended to be protected by SAML SSO, potentially leading to unauthorized data access or modification.

Affected Systems

The vulnerability affects GitLab Community Edition and Enterprise Edition, all versions starting from 18.6 that are earlier than 19.1.8, all 19.2 releases before 19.2.6, and all 19.3 releases before 19.3.2. Upgrading to version 19.1.8, 19.2.6, 19.3.2, or later resolves the missing authentication enforcement issue.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity impact. The EPSS score of < 1% denotes a low likelihood that this vulnerability is actively exploited in the wild. It is not listed in the CISA KEV catalog, so there is no evidence of current widespread exploitation. Because the flaw allows an authenticated user to bypass SAML SSO enforcement, an attacker who has legitimate access credentials can avoid the SSO process and gain access to protected resources. The attack requires that the user exploits a specific context where the authentication check is omitted; the vendor notes that this occurs under certain conditions, so proactive access controls and monitoring are advisable.

Generated by OpenCVE AI on September 20, 2026 at 14:47 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to version 19.1.8, 19.2.6, 19.3.2 or later.
  • Verify that SAML SSO is obligatory for all authentication paths and that no alternate login routes remain enabled.
  • Monitor authentication logs for anomalous sign‑in patterns that might indicate bypass attempts.

Generated by OpenCVE AI on September 20, 2026 at 14:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement checks.
Title Missing Authentication for Critical Function in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-306
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-20T00:45:43.121Z

Reserved: 2026-06-22T15:33:41.496Z

Link: CVE-2026-12910

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:08.721Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:17:16.000

Modified: 2026-09-28T20:04:41.633

Link: CVE-2026-12910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function