Description
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but did not restrict branch deletion, this bypassed the review requirement and caused fresh clones and default-branch API requests to use attacker-controlled content. This vulnerability affected supported GitHub Enterprise Server releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported via the GitHub Bug Bounty program.
Published: 2026-10-06
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized default branch replacement via GraphQL
Action: Immediate Patch
AI Analysis

Impact

A missing authorization flaw in GitHub Enterprise Server’s GraphQL API enables any repository collaborator with write access to delete the repository’s current default branch. By doing so, the attacker can promote a branch of their choosing to become the new default, effectively bypassing pull‑request review requirements if branch deletion is not restricted. The consequence is that subsequent clones and default‑branch API requests will retrieve the attacker‑controlled content, compromising the integrity of the repository code base and potentially facilitating further attacks.

Affected Systems

The vulnerability affects GitHub Enterprise Server releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series. Patches are available in 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2, and all earlier patch releases in those major series remain vulnerable.

Risk and Exploitability

The CVSS score of 6 indicates a moderate severity, while the EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. An attacker who already has repository write access can exploit this via the GraphQL API, which implies the attack vector is internal or via authenticated access to the API.

Generated by OpenCVE AI on October 6, 2026 at 21:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the GitHub Enterprise Server instance to the patched versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, or 3.22.2 as appropriate for your deployment
  • If patching cannot be performed immediately, restrict or remove branch‑deletion permissions from collaborators and enforce strict branch protection rules that prevent deletion of the default branch
  • Audit the GraphQL permission scopes to ensure that write‑access users cannot execute branch‑deletion mutations, and remediate any exposed endpoints that allow such actions

Generated by OpenCVE AI on October 6, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but did not restrict branch deletion, this bypassed the review requirement and caused fresh clones and default-branch API requests to use attacker-controlled content. This vulnerability affected supported GitHub Enterprise Server releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported via the GitHub Bug Bounty program.
Title Missing authorization in GitHub Enterprise Server allowed repository writers to replace default branches via GraphQL
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_P

Published:

Updated: 2026-10-06T18:56:41.101Z

Reserved: 2026-09-30T23:02:34.862Z

Link: CVE-2026-103620

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:39.700

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-103620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses