This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade the GitLab Enterprise Edition instance to version 18.10.8, 18.11.5, 19.0.2, or a later release that includes the fix for the authorization bypass.
- Revoke the Owner role from any accounts that do not require it and review group membership to ensure only trusted users hold that privilege.
- Confirm that SAML identity provider settings in the affected groups are correctly configured and that no user‑controlled keys bypass authorization in the updated version.
- Monitor group access logs for signs of unauthorized activity after the update and run an audit of owned group memberships.
Generated by OpenCVE AI on June 11, 2026 at 12:23 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Fri, 31 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass Through User-Controlled Key in GitLab | |
| Metrics |
ssvc
|
Fri, 31 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected. |
Fri, 31 Jul 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CPEs |
Thu, 11 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
Thu, 11 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality. | |
| Title | Authorization Bypass Through User-Controlled Key in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: GitLab
Published:
Updated: 2026-07-31T18:38:12.936Z
Reserved: 2026-04-17T21:34:28.848Z
Link: CVE-2026-6552
Updated:
Status : Rejected
Published: 2026-06-11T12:16:32.347
Modified: 2026-07-31T19:17:12.343
Link: CVE-2026-6552
No data.
OpenCVE Enrichment
Updated: 2026-06-11T13:30:14Z
No weakness.