UI Misrepresentation Vulnerability in GitHub Enterprise Server
CVE-2026-9106

4.8MEDIUM

Key Information:

Vendor

Github

Vendor
CVE Published:
30 June 2026

What is CVE-2026-9106?

A UI misrepresentation vulnerability in GitHub Enterprise Server allows an OAuth application to gain unauthorized access to an organization's runner management. This occurs when an attacker successfully creates an OAuth application that requests the 'manage_runners:org' scope. The misrepresentation means this scope is not displayed on the user authorization consent screen, putting organizations at risk. Affected versions include all prior to 3.22, with the vulnerability addressed in the releases 3.21.2, 3.20.4, 3.19.8, 3.18.11, and 3.17.17. This issue was reported through the GitHub Bug Bounty program, highlighting the importance of monitoring OAuth permissions carefully.

Affected Version(s)

Enterprise Server 3.17.0 <= 3.17.16

Enterprise Server 3.17.0 <= 3.17.16

Enterprise Server 3.18.0 <= 3.18.10

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VAIBHAV SINGH (@vaib25vicky)
.