CVE-2026-6552

Publication date 11 June 2026

Last updated 7 August 2026


Ubuntu priority

Cvss 3 Severity Score

8.7 · High

Score breakdown

Description

Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.

Read the notes from the security team

Status

Package Ubuntu Release Status
gitlab 26.04 LTS resolute Not in release
25.10 questing Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release

Notes


mdeslaur

GitLab isn't maintainable as a distro package, and was removed from Ubuntu because of this. We will not be fixing security issues in the gitlab package in Xenial.

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.7 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N


Access our resources on patching vulnerabilities