GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context. | |
| Title | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-362 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-09-23T23:04:50.132Z
Reserved: 2026-09-16T15:35:11.125Z
Link: CVE-2026-92628
No data.
Status : Received
Published: 2026-09-24T00:17:22.583
Modified: 2026-09-24T00:17:22.583
Link: CVE-2026-92628
No data.
OpenCVE Enrichment
Updated: 2026-09-24T01:15:07Z
Weaknesses