Missing Authorization Vulnerability in GitHub Enterprise Server
CVE-2026-103620

6MEDIUM

Key Information:

Vendor

Github

Vendor
CVE Published:
6 October 2026

What is CVE-2026-103620?

A missing authorization issue was discovered in GitHub Enterprise Server, allowing repository collaborators with write permissions to delete the current default branch using the GraphQL API. This oversight could enable malicious actors to replace it with a branch they control, effectively bypassing pull request reviews in repositories that don't explicitly restrict branch deletions. As a result, fresh clones of repositories and default-branch API requests risk serving content manipulated by attackers. This vulnerability impacts supported releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series, with fixes available in versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2, as documented in the GitHub Bug Bounty program.

Affected Version(s)

Enterprise Server 3.18.0 < 3.18.*

Enterprise Server 3.19.0 < 3.19.*

Enterprise Server 3.20.0 < 3.20.*

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

taise
.