Junglewise Threat Intelligence

CVE-2026-15783: GitHub Enterprise Server missing authorization in delegated bypass endpoint

CVE-2026-15783 · Severity: info · CVSS 5.3 · Published 2026-07-17

Technologies: GitHub Enterprise Server. Vendors: GitHub.

Executive brief

A security vulnerability in GitHub Enterprise Server allowed users with basic write access to one repository to view sensitive information from other private repositories they were not authorized to see. This included details such as repository names, owner identities, branch names, and commit messages. This could lead to the exposure of internal project structures and development activity across an organization.

Technical details

A missing authorization vulnerability (CWE-862) existed in the delegated bypass endpoint of GitHub Enterprise Server. The endpoint resolved rule suites using attacker-supplied, encoded identifiers without verifying if the requesting user had read permissions for the associated repository. Because these identifiers were sequential, an authenticated attacker with write access to at least one repository could perform an Insecure Direct Object Reference (IDOR) attack to enumerate and extract metadata (repository names, branch names, commit SHAs, and messages) from private repositories across the instance. The issue affected all versions prior to 3.22 and has been patched in several maintenance releases.

Affected products

  • GitHub Enterprise Server < 3.22; fixed in 3.17.18, 3.18.12, 3.19.9, 3.20.5, 3.21.3

Timeline

  • 2026-07-17: disclosed: CVE published by GitHub
  • 2026-07-17: patched: Fixes available in multiple maintenance branches

References