CVE-2026-92874: GitLab

Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope of that token due to improper authorization checks.

Affected products

  • GitLab GitLab: from 18.3.0, before 19.2.7 (fixed in 19.2.7); from 19.3.0, before 19.3.3 (fixed in 19.3.3); version 19.4.0 only

Published 2026-09-24. Last modified 2026-09-28.