Skip to main content
Vulnerability Database/CVE-2026-92874

CVE-2026-92874: GitLab Authorization Bypass Vulnerability

CVE-2026-92874 is an authorization bypass flaw in GitLab CE/EE affecting versions 18.3-19.4.1. Authenticated users with MCP-scoped tokens could perform unauthorized actions. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-92874 Overview

GitLab patched an improper authorization vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) that affects Model Context Protocol (MCP) scoped tokens. An authenticated user holding an MCP-scoped token could perform actions beyond the token's intended scope under certain conditions. The flaw stems from insufficient authorization checks on token-scoped operations and is tracked under CWE-863: Incorrect Authorization. The issue affects GitLab CE/EE versions 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.

Critical Impact

Authenticated attackers with a valid MCP-scoped token can bypass scope restrictions and access GitLab resources or perform operations that should be denied, resulting in limited confidentiality and integrity impact.

Affected Products

  • GitLab CE/EE versions 18.3 through 19.2.6
  • GitLab CE/EE versions 19.3 through 19.3.2
  • GitLab CE/EE versions 19.4 through 19.4.0

Discovery Timeline

  • 2026-09-24 - CVE-2026-92874 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-92874

Vulnerability Analysis

The vulnerability resides in GitLab's authorization enforcement for Model Context Protocol (MCP) scoped tokens. MCP tokens are intended to restrict what an authenticated user or integration can perform when acting through the MCP interface. GitLab failed to fully validate the scope of the presented token against the requested action. This allowed authenticated users to invoke operations outside the boundaries encoded in the token scope. The flaw requires authentication and network access to a GitLab instance, but does not require user interaction or elevated privileges. Successful exploitation leads to unauthorized read or write access to GitLab resources accessible to the underlying user account.

Root Cause

The root cause is an incorrect authorization check ([CWE-863]) in the code path that services MCP-scoped token requests. Scope enforcement logic did not consistently gate all reachable actions, allowing token-bound operations to fall through to broader permissions granted to the authenticated principal.

Attack Vector

An attacker must possess a valid MCP-scoped token issued to an authenticated GitLab account. Using that token over the network, the attacker submits requests to actions that the scope should not permit. Because scope enforcement is incomplete, GitLab processes the request using the underlying user's broader permissions rather than the token's narrower scope. Refer to GitLab Work Item #618614 and the GitLab Release Patch 19.4.1 for additional technical detail.

Detection Methods for CVE-2026-92874

Indicators of Compromise

  • API access logs showing MCP-scoped token requests that succeeded against endpoints outside the declared scope
  • Unexpected read or modification events on projects, groups, or repositories tied to an MCP token's session
  • Sudden increase in API operations from personal access tokens or bot accounts configured with MCP scopes

Detection Strategies

  • Correlate GitLab audit events with token scope metadata to flag requests where the invoked action does not match granted MCP scope
  • Baseline typical MCP token activity per user and alert on deviations in endpoint diversity or request volume
  • Review integration tokens issued to AI assistants, MCP servers, and CI systems for unexpected privilege usage

Monitoring Recommendations

  • Enable GitLab audit event streaming to a centralized log platform for retention and correlation
  • Monitor /api/v4/ endpoints accessed with MCP-scoped tokens and alert on non-MCP resource paths
  • Track token creation and rotation events to identify long-lived tokens that survived the patch window

How to Mitigate CVE-2026-92874

Immediate Actions Required

  • Upgrade GitLab CE/EE to version 19.2.7, 19.3.3, 19.4.1, or later depending on your release branch
  • Rotate all existing MCP-scoped personal and project access tokens after patching
  • Review audit logs for the affected versions to identify any out-of-scope operations performed prior to remediation

Patch Information

GitLab remediated the issue in versions 19.2.7, 19.3.3, and 19.4.1. See the GitLab Release Patch 19.4.1 advisory for full release notes and download instructions. Self-managed instances should apply the patch through the standard GitLab upgrade path.

Workarounds

  • Revoke MCP-scoped tokens until the upgrade can be completed
  • Restrict MCP feature usage to trusted users and disable integrations that rely on MCP tokens where feasible
  • Enforce network-level access controls to limit which clients can reach the GitLab API
bash
# Verify installed GitLab version and confirm patched build
sudo gitlab-rake gitlab:env:info | grep -i version

# List active personal access tokens through the Rails console for review
sudo gitlab-rails runner "PersonalAccessToken.active.where('scopes LIKE ?', '%mcp%').each { |t| puts [t.id, t.user_id, t.name, t.scopes].inspect }"

# Revoke a specific token by ID after identifying misuse
sudo gitlab-rails runner "PersonalAccessToken.find(<TOKEN_ID>).revoke!"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.