CVE-2026-5845 Details
Description
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context, which could be chained with token revocation timing and SSH push attribution to obtain and reuse a victim-scoped token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program.
A vulnerability in GitHub Enterprise Server's handling of scoped user-to-server tokens can lead to unauthorized access to private repositories. This issue arises when a GitHub App installation is revoked or deleted, causing the authorization to incorrectly revert to a global context. As a result, an authenticated attacker can access resources outside the intended scope, potentially including write operations. The vulnerability exploits timing issues in token revocation and SSH push attribution to access private repository contents without the victim's knowledge. This vulnerability affects all versions of GitHub Enterprise Server prior to 3.21.
Users can upgrade to GitHub Enterprise Server versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, or 3.14.26.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.github.com/en/[email protected]/admin/release-notes#3.14.26 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.15.21 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.16.17 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.17.14 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.18.8 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.19.5 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.20.1 | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| github enterprise server | < 3.14.26 >= 3.15.0, < 3.15.21 >= 3.16.0, < 3.16.17 >= 3.17.0, < 3.17.14 >= 3.18.0, < 3.18.8 >= 3.19.0, < 3.19.5 3.20.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | New CVE Received | [email protected] |