CVE-2026-92874

Summary

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope of that token due to improper authorization checks.

Affected Software

VendorProductVersion RangeStatus
GitLabGitLab18.3 < 19.2.7affected
GitLabGitLab19.3 < 19.3.3affected
GitLabGitLab19.4 < 19.4.1affected

Weaknesses

  • CWE-863: CWE-863: Incorrect Authorization

References