MEDIUM
CVE-2026-12910
CVSS
5.4
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement checks.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
0.32%
Probability of exploitation in next 30 days
25.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.