Authorization Bypass in GitHub Enterprise Server
CVE-2026-75101

6MEDIUM

Key Information:

Vendor

Github

Vendor
CVE Published:
22 September 2026

What is CVE-2026-75101?

An authorization bypass vulnerability was discovered in GitHub Enterprise Server, enabling authenticated users to access the raw diff or patch of pull requests in private repositories without proper authorization. The issue stemmed from the access tokens being linked to repository names and pull request numbers instead of unique identifiers. As a result, an attacker could potentially create a repository that matched a target's repository name and pull request number to exploit this flaw. To successfully exploit this vulnerability, an attacker needed to know the target repository's name and a valid pull request number. The vulnerability impacts all earlier versions of GitHub Enterprise Server, and patches were released in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6.

Affected Version(s)

Enterprise Server 3.17.0 < 3.17.*

Enterprise Server 3.18.0 < 3.18.*

Enterprise Server 3.19.0 < 3.19.*

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

syvb
.