CVE-2026-9106 Details
Description
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
A UI misrepresentation vulnerability in GitHub Enterprise Server prior to 3.22 allowed an OAuth application to gain unintended access to an organization's runner management. This was possible by creating an OAuth application that requested the manage_runners:org scope and directing a user to authorize it. The scope was not displayed on the authorization consent screen, leading to unauthorized access.
This vulnerability has been fixed in GitHub Enterprise Server versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, and 3.16.20.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| github enterprise server | < 3.16.20 >= 3.17.0, < 3.17.17 >= 3.18.0, < 3.18.11 >= 3.19.0, < 3.19.8 >= 3.20.0, < 3.20.4 >= 3.21.0, < 3.21.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | New CVE Received | [email protected] |