Missing Authorization Vulnerability in GitHub Enterprise Server
CVE-2026-9132
What is CVE-2026-9132?
A missing authorization vulnerability was discovered in GitHub Enterprise Server, enabling an authenticated user to access private repository source code without the necessary permissions. The flaw lies in the Copilot pull request description diff summary endpoint, which allows for cross-repository comparison without proper authorization checks. This means that any authenticated user with read access to one repository could potentially view source code from other private repositories they are not authorized to access. This impacts all versions of GitHub Enterprise Server prior to 3.21, with patches provided in versions 3.17.17, 3.18.11, 3.19.8, and 3.20.4, ensuring better security and compliance for source code protection.
Affected Version(s)
Enterprise Server 3.17.0 <= 3.17.16
Enterprise Server 3.18.0 <= 3.18.10
Enterprise Server 3.19.0 <= 3.19.7