CVE-2026-6552EPSS p28.2%

CVE-2026-6552CVE-2026-6552

Description

Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.

Scoring

EPSS0.36% probability of exploitation · percentile 28.2% · 2026-07-31T12:03:43Z
Last modified2026-07-31
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.