CVE-2026-92874 Overview
GitLab patched an improper authorization vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) that affects Model Context Protocol (MCP) scoped tokens. An authenticated user holding an MCP-scoped token could perform actions beyond the token's intended scope under certain conditions. The flaw stems from insufficient authorization checks on token-scoped operations and is tracked under CWE-863: Incorrect Authorization. The issue affects GitLab CE/EE versions 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.
Critical Impact
Authenticated attackers with a valid MCP-scoped token can bypass scope restrictions and access GitLab resources or perform operations that should be denied, resulting in limited confidentiality and integrity impact.
Affected Products
- GitLab CE/EE versions 18.3 through 19.2.6
- GitLab CE/EE versions 19.3 through 19.3.2
- GitLab CE/EE versions 19.4 through 19.4.0
Discovery Timeline
- 2026-09-24 - CVE-2026-92874 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-92874
Vulnerability Analysis
The vulnerability resides in GitLab's authorization enforcement for Model Context Protocol (MCP) scoped tokens. MCP tokens are intended to restrict what an authenticated user or integration can perform when acting through the MCP interface. GitLab failed to fully validate the scope of the presented token against the requested action. This allowed authenticated users to invoke operations outside the boundaries encoded in the token scope. The flaw requires authentication and network access to a GitLab instance, but does not require user interaction or elevated privileges. Successful exploitation leads to unauthorized read or write access to GitLab resources accessible to the underlying user account.
Root Cause
The root cause is an incorrect authorization check ([CWE-863]) in the code path that services MCP-scoped token requests. Scope enforcement logic did not consistently gate all reachable actions, allowing token-bound operations to fall through to broader permissions granted to the authenticated principal.
Attack Vector
An attacker must possess a valid MCP-scoped token issued to an authenticated GitLab account. Using that token over the network, the attacker submits requests to actions that the scope should not permit. Because scope enforcement is incomplete, GitLab processes the request using the underlying user's broader permissions rather than the token's narrower scope. Refer to GitLab Work Item #618614 and the GitLab Release Patch 19.4.1 for additional technical detail.
Detection Methods for CVE-2026-92874
Indicators of Compromise
- API access logs showing MCP-scoped token requests that succeeded against endpoints outside the declared scope
- Unexpected read or modification events on projects, groups, or repositories tied to an MCP token's session
- Sudden increase in API operations from personal access tokens or bot accounts configured with MCP scopes
Detection Strategies
- Correlate GitLab audit events with token scope metadata to flag requests where the invoked action does not match granted MCP scope
- Baseline typical MCP token activity per user and alert on deviations in endpoint diversity or request volume
- Review integration tokens issued to AI assistants, MCP servers, and CI systems for unexpected privilege usage
Monitoring Recommendations
- Enable GitLab audit event streaming to a centralized log platform for retention and correlation
- Monitor /api/v4/ endpoints accessed with MCP-scoped tokens and alert on non-MCP resource paths
- Track token creation and rotation events to identify long-lived tokens that survived the patch window
How to Mitigate CVE-2026-92874
Immediate Actions Required
- Upgrade GitLab CE/EE to version 19.2.7, 19.3.3, 19.4.1, or later depending on your release branch
- Rotate all existing MCP-scoped personal and project access tokens after patching
- Review audit logs for the affected versions to identify any out-of-scope operations performed prior to remediation
Patch Information
GitLab remediated the issue in versions 19.2.7, 19.3.3, and 19.4.1. See the GitLab Release Patch 19.4.1 advisory for full release notes and download instructions. Self-managed instances should apply the patch through the standard GitLab upgrade path.
Workarounds
- Revoke MCP-scoped tokens until the upgrade can be completed
- Restrict MCP feature usage to trusted users and disable integrations that rely on MCP tokens where feasible
- Enforce network-level access controls to limit which clients can reach the GitLab API
# Verify installed GitLab version and confirm patched build
sudo gitlab-rake gitlab:env:info | grep -i version
# List active personal access tokens through the Rails console for review
sudo gitlab-rails runner "PersonalAccessToken.active.where('scopes LIKE ?', '%mcp%').each { |t| puts [t.id, t.user_id, t.name, t.scopes].inspect }"
# Revoke a specific token by ID after identifying misuse
sudo gitlab-rails runner "PersonalAccessToken.find(<TOKEN_ID>).revoke!"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
