Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-15783PATCHED
github · enterprise server

Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites

Description

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch names, commit SHAs, commit messages, and the pushing actor. The delegated bypass endpoint resolved a rule suite directly from an attacker-supplied, encoded identifier without verifying that the requesting user could read the rule suite's repository, and because these identifiers are sequential an attacker could enumerate them across the instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.18, 3.18.12, 3.19.9, 3.20.5, and 3.21.3. This vulnerability was reported via the GitHub Bug Bounty program.

Affected Products

VendorProductVersions
githubenterprise server3.17.0, 3.18.0, 3.19.0, 3.20.0, 3.21.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftgithub enterprisecert_advisory90%

References

  • https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.18(release-notes)
  • https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.12(release-notes)
  • https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.9(release-notes)
  • https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.5(release-notes)
  • https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.3(release-notes)

Related News (2 articles)

Tier B
BSI Advisories23d ago
[NEU] [hoch] Microsoft GitHub Enterprise Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB26d ago
CVE-2026-15783 | GitHub Enterprise Server up to 3.21.2 Delegated Bypass Endpoint authorization
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.17.183.18.123.19.93.20.53.21.3
CWECWE-862
PublishedJul 17, 2026
Last enriched26d agov2
Trending Score2
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-17556
Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
Trending: 20
NONECVE-2026-15996
Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
Trending: 13
CRITICALCVE-2026-15343
Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
Trending: 4
NONECVE-2026-15007
Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration
Trending: 2
HIGHCVE-2026-50510EXP
GitHub Copilot Remote Code Execution Vulnerability
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: affectedVersions, patchAvailable
Jul 17, 2026
Patch Available
Jul 17, 2026

Version History

v2
Last enriched 26d ago
v2Tier C26d ago

Article specifies exact vulnerable version ranges (up to 3.17.17/3.18.11/3.19.8/3.20.4/3.21.2) and confirms fixed versions (3.17.18, 3.18.12, 3.19.9, 3.20.5, 3.21.3), providing more precise version information than the current record's generic major version entries.

affectedVersionspatchAvailable
via VulDB
v126d ago

Initial creation