Race Condition Vulnerability in GitLab CE/EE Affecting Multiple Versions
CVE-2026-92628

3.1LOW

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-92628?

A race condition in GitLab CE/EE has been identified, impacting various versions prior to specified patches. This vulnerability affects the search functionality of the MCP tool, where shared state handling could result in the incorrect return of search results under a different user context. This discrepancy could mislead users into receiving information accessible to others, potentially exposing sensitive data. It is crucial for users of the affected GitLab versions to apply the recommended patches promptly to mitigate this risk.

Affected Version(s)

GitLab 18.6 < 19.2.7

GitLab 19.3 < 19.3.3

GitLab 19.4 < 19.4.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member Chris Bonk
.