Missing Authorization Vulnerability in GitHub Enterprise Server
CVE-2026-103620
What is CVE-2026-103620?
A missing authorization issue was discovered in GitHub Enterprise Server, allowing repository collaborators with write permissions to delete the current default branch using the GraphQL API. This oversight could enable malicious actors to replace it with a branch they control, effectively bypassing pull request reviews in repositories that don't explicitly restrict branch deletions. As a result, fresh clones of repositories and default-branch API requests risk serving content manipulated by attackers. This vulnerability impacts supported releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series, with fixes available in versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2, as documented in the GitHub Bug Bounty program.
Affected Version(s)
Enterprise Server 3.18.0 < 3.18.*
Enterprise Server 3.19.0 < 3.19.*
Enterprise Server 3.20.0 < 3.20.*