Improper Authorization Vulnerability in GitHub Enterprise Server
CVE-2026-5512

5.3MEDIUM

Key Information:

Vendor

Github

Vendor
CVE Published:
21 April 2026

What is CVE-2026-5512?

An improper authorization vulnerability exists within GitHub Enterprise Server that enables authenticated attackers to discover the names of private repositories using their numeric IDs. The mobile upload policy API endpoint fails to conduct an early authorization check, potentially exposing details through validation error messages that include complete repository names, even when access is not granted. This security flaw affects multiple versions of GitHub Enterprise Server prior to version 3.21 and was disclosed through the GitHub Bug Bounty program.

Affected Version(s)

Enterprise Server 3.14.0 <= 3.14.25

Enterprise Server 3.14.0 <= 3.14.25

Enterprise Server 3.15.0 <= 3.15.20

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ahacker1
.