Authorization Bypass in GitHub Enterprise Server Allows Unrestricted Pull Requests
CVE-2026-1999
What is CVE-2026-1999?
An authorization bypass vulnerability in GitHub Enterprise Server allows attackers to merge unauthorized pull requests into repositories. This issue particularly affects repositories that permit forking and occurs when attackers exploit the enable_auto_merge mutation through their own fork. The attack requires certain conditions like a clean pull request status and branches without branch protection rules. This vulnerability has been addressed in versions 3.19.2, 3.18.5, and 3.17.11, following reports via the GitHub Bug Bounty program.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Enterprise Server 3.14.0
Enterprise Server 3.14.0 < 3.14.22
Enterprise Server 3.15.0 < 3.15.17
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved