CVE-2026-92628: 
GitLab Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-92628 is a race condition vulnerability in GitLab CE/EE affecting the MCP (Model Context Protocol) search tool's shared state handling. Under certain timing conditions, search results could be returned under an incorrect user context, constituting an information disclosure flaw. It affects all GitLab CE/EE versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. Disclosed on September 24, 2026, it carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, GitLab Patch Release).

Détails techniques

The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization — Race Condition). The MCP search tool maintains shared state that is not properly synchronized across concurrent requests; when two or more requests race, the state from one user's search context can bleed into another user's response. Exploitation requires an authenticated attacker with low privileges and a network-accessible GitLab instance, but the high attack complexity (timing-dependent) makes reliable exploitation difficult. No public proof-of-concept or detailed technical write-up has been published (GitHub Advisory).

Impact

Successful exploitation results in limited confidentiality impact: an authenticated low-privileged user may receive search results belonging to another user's session, potentially exposing sensitive repository names, code snippets, issue content, or other data surfaced by the MCP search tool. There is no integrity or availability impact, and the scope is unchanged, meaning the vulnerability does not enable lateral movement or privilege escalation beyond the information disclosure itself (GitHub Advisory, GitLab Patch Release).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity (race condition timing requirement) further limits practical exploitability (GitHub Advisory).

Atténuation et solutions de contournement

GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. Users running any version from 18.6 through 19.2.6, 19.3.0 through 19.3.2, or 19.4.0 should upgrade to the appropriate fixed release immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Patch Release, GitHub Advisory).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté GitLab Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiSep 24, 2026
CVE-2026-92874MEDIUM5.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiSep 24, 2026
CVE-2026-92530MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiSep 24, 2026
CVE-2026-92529MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiSep 24, 2026
CVE-2026-92628LOW3.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiSep 24, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités