OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-75101

MEDIUM · CVSS 6.5 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

An authorization bypass vulnerability in GitHub Enterprise Server allows authenticated users to access raw diffs or patches of pull requests in private repositories without proper authorization. This occurs because access tokens are scoped to repository names and pull request numbers, enabling attackers to exploit this by creating repositories with matching names and numbers. Organizations using affected versions prior to 3.22 should prioritize patching to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75101
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
GitHub

Original NVD Description

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and pull request number rather than to a globally unique repository identifier, so an attacker who created a repository and pull request matching a target's repository name and pull request number could use a token for their own repository to retrieve the private pull request's contents. Exploitation required the attacker to know the target repository's name and a valid pull request number. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6. This vulnerability was reported via the GitHub Bug Bounty program.

Related CVEs

Other vulnerabilities affecting the same vendor(s)