CVE-2026-6552: Authorization Bypass Through User-Controlled Key in GitLab
Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6552?
The severity of CVE-2026-6552 is high with a CVSS score of 8.7.
How do I fix CVE-2026-6552?
To fix CVE-2026-6552, upgrade GitLab EE to version 18.10.8, 18.11.5, or 19.0.2 or above.
What is CVE-2026-6552 about?
CVE-2026-6552 involves an authorization bypass that could allow an authenticated user with the Owner role to take over another group member's GitLab account.
Which versions of GitLab are affected by CVE-2026-6552?
CVE-2026-6552 affects all versions of GitLab EE from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
Who is at risk for CVE-2026-6552?
Authenticated users with group Owner role may be at risk for CVE-2026-6552 due to improper authorization.