Authorization Flaw in GitLab Affecting Multiple Versions
CVE-2026-92874
5.4MEDIUM
What is CVE-2026-92874?
An issue in GitLab CE/EE allowed authenticated users with a specific MCP-scoped token to perform actions outside of the intended permissions. This vulnerability arose due to insufficient authorization checks, potentially leading to unauthorized actions. GitLab has since issued a patch to address the issue and ensure greater security.
Affected Version(s)
GitLab 18.3 < 19.2.7
GitLab 19.3 < 19.3.3
GitLab 19.4 < 19.4.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member Amr Taha