Authorization Flaw in GitLab Affecting Multiple Versions
CVE-2026-92874

5.4MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-92874?

An issue in GitLab CE/EE allowed authenticated users with a specific MCP-scoped token to perform actions outside of the intended permissions. This vulnerability arose due to insufficient authorization checks, potentially leading to unauthorized actions. GitLab has since issued a patch to address the issue and ensure greater security.

Affected Version(s)

GitLab 18.3 < 19.2.7

GitLab 19.3 < 19.3.3

GitLab 19.4 < 19.4.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member Amr Taha
.