Gitlab · Gitlab · CVE-2026-92628
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 18.6 through 19.2.6
GitLab CE/EE versions 19.3 through 19.3.2
GitLab CE/EE versions 19.4
**Description**
A race condition exists in the shared state handling of the MCP search tool. This occurs when multiple processes access a shared resource concurrently without proper synchronization, which could lead to search results being returned under an incorrect user context.
**Recommendations**
Update to version 19.2.7 or later.
Update to version 19.3.3 or later.
Update to version 19.4.1 or later.