CVE-2026-12910
Missing Authentication for Critical Function in GitLab
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement checks.
In plain language
AI Low urgencyGitLab versions from 18.6 through the affected 19.x releases have a sign-in control gap; most small businesses should schedule an upgrade soon.
An authenticated-user authentication-enforcement flaw (CWE-306) can, under certain conditions, let users bypass GitLab SAML SSO sign-in restrictions.
What to do now
- Check your GitLab version and whether your organization requires SAML single sign-on for access.
- Upgrade GitLab 19.1 to 19.1.8 or later, 19.2 to 19.2.6 or later, or 19.3 to 19.3.2 or later.
- Review recent GitLab sign-ins for accounts that accessed GitLab without completing your required company sign-in process.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-12910 and every CVE in our database. Create a free account — no credit card required.
Create Free Account