PT-2026-54645 · Github · Enterprise Server+1

·

CVE-2026-14340

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions prior to 3.22
Description An incorrect authorization issue allows a user-to-server token scoped to a GitHub App installation to perform write operations on public repositories outside its intended scope. This occurs because the authorization check only verifies if the installation has read permissions on the target repository instead of confirming the token's installation was explicitly granted access. An attacker possessing a victim's user-to-server token could create issues, issue comments, commit comments, and private vulnerability reports on any public repository, appearing as the victim user without indicating app involvement.
Recommendations Update to version 3.21.2 Update to version 3.20.4 Update to version 3.19.8 Update to version 3.18.11 Update to version 3.17.17 Update to version 3.16.20

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14340

Affected Products

Enterprise Server
Github Pages