CVE-2026-92628: GitLab

Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context.

Affected products

  • GitLab GitLab: from 18.6.0, before 19.2.7 (fixed in 19.2.7); from 19.3.0, before 19.3.3 (fixed in 19.3.3); version 19.4.0 only

Published 2026-09-24. Last modified 2026-09-28.