Authorization Bypass in GitHub Enterprise Server Allows Unrestricted Pull Requests
CVE-2026-1999
Key Information:
- Vendor
Github
- Status
- Vendor
- CVE Published:
- 18 February 2026
Badges
What is CVE-2026-1999?
An authorization bypass vulnerability in GitHub Enterprise Server allows attackers to merge unauthorized pull requests into repositories. This issue particularly affects repositories that permit forking and occurs when attackers exploit the enable_auto_merge mutation through their own fork. The attack requires certain conditions like a clean pull request status and branches without branch protection rules. This vulnerability has been addressed in versions 3.19.2, 3.18.5, and 3.17.11, following reports via the GitHub Bug Bounty program.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Enterprise Server 3.14.0
Enterprise Server 3.14.0 < 3.14.22
Enterprise Server 3.15.0 < 3.15.17
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved