CVE-2026-92628: 
GitLab Análisis y mitigación de vulnerabilidades

Vista general

CVE-2026-92628 is a race condition vulnerability in GitLab CE/EE affecting the MCP (Model Context Protocol) search tool's shared state handling. Under certain timing conditions, search results could be returned under an incorrect user context, constituting an information disclosure flaw. It affects all GitLab CE/EE versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. Disclosed on September 24, 2026, it carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, GitLab Patch Release).

Técnicas

The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization — Race Condition). The MCP search tool maintains shared state that is not properly synchronized across concurrent requests; when two or more requests race, the state from one user's search context can bleed into another user's response. Exploitation requires an authenticated attacker with low privileges and a network-accessible GitLab instance, but the high attack complexity (timing-dependent) makes reliable exploitation difficult. No public proof-of-concept or detailed technical write-up has been published (GitHub Advisory).

Impacto

Successful exploitation results in limited confidentiality impact: an authenticated low-privileged user may receive search results belonging to another user's session, potentially exposing sensitive repository names, code snippets, issue content, or other data surfaced by the MCP search tool. There is no integrity or availability impact, and the scope is unchanged, meaning the vulnerability does not enable lateral movement or privilege escalation beyond the information disclosure itself (GitHub Advisory, GitLab Patch Release).

Explotabilidad

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity (race condition timing requirement) further limits practical exploitability (GitHub Advisory).

Mitigación y soluciones alternativas

GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. Users running any version from 18.6 through 19.2.6, 19.3.0 through 19.3.2, or 19.4.0 should upgrade to the appropriate fixed release immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Patch Release, GitHub Advisory).

Recursos adicionales


Fuente: Este informe se generó utilizando IA

Relacionado GitLab Vulnerabilidades:

CVE ID

Severidad

Puntuación

Tecnologías

Nombre del componente

Exploit de CISA KEV

Tiene arreglo

Fecha de publicación

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSíSep 24, 2026
CVE-2026-92874MEDIUM5.4
  • GitLab logoGitLab
  • gitlab
NoSíSep 24, 2026
CVE-2026-92530MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
NoSíSep 24, 2026
CVE-2026-92529MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSíSep 24, 2026
CVE-2026-92628LOW3.1
  • GitLab logoGitLab
  • gitlab
NoSíSep 24, 2026

Evaluación gratuita de vulnerabilidades

Compare su postura de seguridad en la nube

Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.

Solicitar evaluación

Recursos adicionales de Wiz

Obtén una demostración personalizada

¿Listo para ver a Wiz en acción?

"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
David EstlickCISO
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
Adam FletcherJefe de Seguridad
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."
Greg PoniatowskiJefe de Gestión de Amenazas y Vulnerabilidades