Gitlab · Gitlab · CVE-2026-92874
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 18.3 through 19.2.6
GitLab CE/EE versions 19.3 through 19.3.2
GitLab CE/EE versions 19.4
**Description**
Improper authorization checks may allow an authenticated user possessing an MCP-scoped token to perform actions that exceed the intended scope of that token.
**Recommendations**
Update to version 19.2.7 or later.
Update to version 19.3.3 or later.
Update to version 19.4.1 or later.