Security Advisory

CVE-2026-6552

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-11 10:20:21
Last updated 2026-07-31 18:38:12
Assigner GitLab
CVSS score 8.7
State REJECTED

Description

This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.