Intel

AIKIDO-2026-960548

gitlab-ce is vulnerable to Improper Authentication

Improper AuthenticationCVE-2026-12910 Published 3 days ago

54

Medium Risk

This Affects:

OSgitlab-ce
18.6.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

SAML SSO sign-in restriction enforcement misses required authentication checks in some flows. An authenticated user can bypass those SSO restrictions and authenticate without SSO. The fix enforces the SAML SSO checks on the affected sign-in paths.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and enforce SAML SSO sign-in restrictions.

Background info

gitlab-ce is vulnerable to Improper Authentication in versions 18.6.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform