Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope of that token due to improper authorization checks.
Published: 2026-09-23
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Excessive permissions via MCP‑scoped token resulting in unauthorized actions within GitLab
Action: Apply patch
AI Analysis

Impact

An authenticated user possessing an MCP‑scoped token can perform actions beyond the intended scope of that token because GitLab’s authorization checks are insufficient. This flaw enables the user to execute privileged operations that they should not be allowed to, potentially exposing repository data, configuration, or other sensitive information. The weakness is classified as CWE-863, Improper Authorization.

Affected Systems

GitLab Community Edition and Enterprise Edition versions starting at 18.3 up to, but not including, 19.2.7, 19.3 up to 19.3.3, and 19.4 up to 19.4.1 are affected. All other newer releases are exempt.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The required conditions for exploitation include possessing valid GitLab credentials and an MCP‑scoped token, implying that the attacker must be authenticated within the same instance. Consequently, the attack vector is internal authenticated, and while the risk is moderate, it remains significant for organizations that issue MCP‑scoped tokens to users without enforcing strict least‑privilege controls.

Generated by OpenCVE AI on September 24, 2026 at 00:23 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above.


OpenCVE Recommended Actions

  • Upgrade to GitLab 19.2.7, 19.3.3, 19.4.1, or a later patched release
  • Limit issuance of MCP‑scoped tokens, ensuring they are granted only to users who absolutely need them and are scoped narrowly
  • Review existing MCP‑scoped tokens and revoke or tighten scopes for any that are unnecessary or too broad

Generated by OpenCVE AI on September 24, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope of that token due to improper authorization checks.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-23T23:04:55.130Z

Reserved: 2026-09-17T06:34:15.295Z

Link: CVE-2026-92874

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T00:17:22.713

Modified: 2026-09-24T00:17:22.713

Link: CVE-2026-92874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T00:30:07Z

Weaknesses