
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-92628 is a race condition vulnerability in GitLab CE/EE affecting the MCP (Model Context Protocol) search tool's shared state handling. Under certain timing conditions, search results could be returned under an incorrect user context, constituting an information disclosure flaw. It affects all GitLab CE/EE versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. Disclosed on September 24, 2026, it carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization — Race Condition). The MCP search tool maintains shared state that is not properly synchronized across concurrent requests; when two or more requests race, the state from one user's search context can bleed into another user's response. Exploitation requires an authenticated attacker with low privileges and a network-accessible GitLab instance, but the high attack complexity (timing-dependent) makes reliable exploitation difficult. No public proof-of-concept or detailed technical write-up has been published (GitHub Advisory).
Successful exploitation results in limited confidentiality impact: an authenticated low-privileged user may receive search results belonging to another user's session, potentially exposing sensitive repository names, code snippets, issue content, or other data surfaced by the MCP search tool. There is no integrity or availability impact, and the scope is unchanged, meaning the vulnerability does not enable lateral movement or privilege escalation beyond the information disclosure itself (GitHub Advisory, GitLab Patch Release).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity (race condition timing requirement) further limits practical exploitability (GitHub Advisory).
GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. Users running any version from 18.6 through 19.2.6, 19.3.0 through 19.3.2, or 19.4.0 should upgrade to the appropriate fixed release immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Patch Release, GitHub Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"