Authorization Bypass in GitHub Enterprise Server Allows Unrestricted Pull Requests
CVE-2026-1999

7.2HIGH

Key Information:

Vendor

Github

Vendor
CVE Published:
18 February 2026

What is CVE-2026-1999?

An authorization bypass vulnerability in GitHub Enterprise Server allows attackers to merge unauthorized pull requests into repositories. This issue particularly affects repositories that permit forking and occurs when attackers exploit the enable_auto_merge mutation through their own fork. The attack requires certain conditions like a clean pull request status and branches without branch protection rules. This vulnerability has been addressed in versions 3.19.2, 3.18.5, and 3.17.11, following reports via the GitHub Bug Bounty program.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Enterprise Server 3.14.0

Enterprise Server 3.14.0 < 3.14.22

Enterprise Server 3.15.0 < 3.15.17

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ahacker1
.