Database/Control plane, storage & DevOps
GitLab CE/EE: missing enforcement checks let an authenticated user bypass SAML SSO restrictions
Impact
Missing authentication enforcement checks allowed an authenticated user, under conditions GitLab does not detail, to sign in without going through SAML SSO. Where SSO is the control that ties repository and pipeline access to the identity provider - including offboarding, MFA and conditional access - a bypass means those gates can be sidestepped for the source and CI system that builds what runs on the fleet. Rated low for both confidentiality and integrity, so this is a control weakening rather than direct data theft. Affects 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Distinct from CVE-2026-82837 in the same release: different flaw, different affected range.
Who can reach it
An authenticated GitLab user reaching the instance over the network; low privileges required, no user interaction.
What to do
Upgrade self-managed GitLab to 19.1.8, 19.2.6 or 19.3.2 - a package upgrade and service restart on the GitLab instance. Review sign-in audit events for group members who authenticated without SSO in the affected window. GitLab.com is already patched.
References
Related entries
- GitLab EE: missing namespace validation lets a user apply compliance frameworks from namespaces they cannot accessCVE-2026-4398 · GitLab EE self-managed (compliance framework namespace validation)Medium
- LibreNMS: reflected XSS in the Proxmox view runs script in a logged-in monitoring user's sessionCVE-2026-45694 · LibreNMS (Proxmox application view, instance and vmid parameters)Medium
- Strimzi: partial Entity Operator deployments still get both operators' RBAC, over-granting the SACVE-2026-55226 · Strimzi Kafka Operator (Entity Operator ServiceAccount RBAC)Medium
- Jenkins Stapler: form binding writes public static fields, applying changes instance-wideCVE-2026-84654 · Jenkins Stapler (form data binding to public static fields)Medium
- Jenkins Pipeline: Build Step Plugin: downstream builds cancelled without Item/Cancel permission checkCVE-2026-84660 · Jenkins Pipeline: Build Step Plugin (build and waitForBuild step cancellation)Medium
- Jenkins Pipeline: Groovy Libraries plugin: CSRF lets an unauthenticated attacker delete library cachesCVE-2026-84663 · Jenkins Pipeline: Groovy Libraries Plugin (shared library cache deletion endpoint)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.