Vulnerability  ·  2026-09-25

GitLab MCP: MCP-scoped token can perform actions beyond scope (CVE-2026-92874), Duo AI governance bypass by developer role (CVE-2026-92529), MCP search race-condition context leak (CVE-2026-92628)

VulnerabilityLow impactGlobalCVE-2026-92874
GitLab's 19.4.1 patch release (2026-09-24) fixed three agentic-security issues: (1) MCP-scoped tokens could perform actions beyond their intended scope due to improper authorization (CVE-2026-92874, CVSS 5.4, CE/EE 18.3+); (2) an authenticated developer-role user could bypass admin-configured AI tool governance controls for workspace... AI (CVE-2026-92529, CVSS 4.3, EE 19.1+); (3) under a race condition, the MCP search tool's shared-state handling could return search results under an incorrect user context (CVE-2026-92628, CVSS 3.1, CE/EE 18.6+).
GitLab's MCP server and Duo AI assistant are the agentic control surfaces of the software supply chain; scope-bypass and cross-user-context leaks in them let AI/MCP integrations read or act beyond delegated boundaries and let developers bypass admin AI governance controls.
Authenticated user with MCP-scoped token or developer role exercises MCP tools / Duo AI settings beyond intended scope; race condition returns search results under another user's context.
GitLab CE/EE (MCP + Duo AI) affected version ranges; fixed in 19.2.7/19.3.3/19.4.1
Upgrade to GitLab 19.2.7/19.3.3/19.4.1 or later.
NVD CVE-2026-92874GitLab patch release 19.4.1
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →