CVE-2026-92628:
GitLab Análisis y mitigación de vulnerabilidades
Vista general
CVE-2026-92628 is a race condition vulnerability in GitLab CE/EE affecting the MCP (Model Context Protocol) search tool's shared state handling. Under certain timing conditions, search results could be returned under an incorrect user context, constituting an information disclosure flaw. It affects all GitLab CE/EE versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. Disclosed on September 24, 2026, it carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, GitLab Patch Release).
Técnicas
The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization — Race Condition). The MCP search tool maintains shared state that is not properly synchronized across concurrent requests; when two or more requests race, the state from one user's search context can bleed into another user's response. Exploitation requires an authenticated attacker with low privileges and a network-accessible GitLab instance, but the high attack complexity (timing-dependent) makes reliable exploitation difficult. No public proof-of-concept or detailed technical write-up has been published (GitHub Advisory).
Impacto
Successful exploitation results in limited confidentiality impact: an authenticated low-privileged user may receive search results belonging to another user's session, potentially exposing sensitive repository names, code snippets, issue content, or other data surfaced by the MCP search tool. There is no integrity or availability impact, and the scope is unchanged, meaning the vulnerability does not enable lateral movement or privilege escalation beyond the information disclosure itself (GitHub Advisory, GitLab Patch Release).
Explotabilidad
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity (race condition timing requirement) further limits practical exploitability (GitHub Advisory).
Mitigación y soluciones alternativas
GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. Users running any version from 18.6 through 19.2.6, 19.3.0 through 19.3.2, or 19.4.0 should upgrade to the appropriate fixed release immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Patch Release, GitHub Advisory).
Recursos adicionales
Fuente: Este informe se generó utilizando IA
Relacionado GitLab Vulnerabilidades:
Evaluación gratuita de vulnerabilidades
Compare su postura de seguridad en la nube
Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.
Recursos adicionales de Wiz
Obtén una demostración personalizada
¿Listo para ver a Wiz en acción?
"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."