Incorrect authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-92874
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to perform actions beyond the intended scope of an MCP-scoped token.
The vulnerability exists due to improper authorization checks in MCP API scope enforcement when processing requests with an MCP-scoped token. A remote user can use an MCP-scoped token to perform actions beyond the intended scope of an MCP-scoped token.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-92874
Gitlab Community Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1