UI Misrepresentation Vulnerability in GitHub Enterprise Server
CVE-2026-9106
What is CVE-2026-9106?
A UI misrepresentation vulnerability in GitHub Enterprise Server allows an OAuth application to gain unauthorized access to an organization's runner management. This occurs when an attacker successfully creates an OAuth application that requests the 'manage_runners:org' scope. The misrepresentation means this scope is not displayed on the user authorization consent screen, putting organizations at risk. Affected versions include all prior to 3.22, with the vulnerability addressed in the releases 3.21.2, 3.20.4, 3.19.8, 3.18.11, and 3.17.17. This issue was reported through the GitHub Bug Bounty program, highlighting the importance of monitoring OAuth permissions carefully.
Affected Version(s)
Enterprise Server 3.17.0 <= 3.17.16
Enterprise Server 3.17.0 <= 3.17.16
Enterprise Server 3.18.0 <= 3.18.10