Missing Authorization Vulnerability in GitHub Enterprise Server
CVE-2026-9132

6MEDIUM

Key Information:

Vendor

Github

Vendor
CVE Published:
30 June 2026

What is CVE-2026-9132?

A missing authorization vulnerability was discovered in GitHub Enterprise Server, enabling an authenticated user to access private repository source code without the necessary permissions. The flaw lies in the Copilot pull request description diff summary endpoint, which allows for cross-repository comparison without proper authorization checks. This means that any authenticated user with read access to one repository could potentially view source code from other private repositories they are not authorized to access. This impacts all versions of GitHub Enterprise Server prior to 3.21, with patches provided in versions 3.17.17, 3.18.11, 3.19.8, and 3.20.4, ensuring better security and compliance for source code protection.

Affected Version(s)

Enterprise Server 3.17.0 <= 3.17.16

Enterprise Server 3.18.0 <= 3.18.10

Enterprise Server 3.19.0 <= 3.19.7

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seokchan Yoon
.