Description
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value updates were applied without verifying the actor's repository write permissions. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.24, 3.15.19, 3.16.15, 3.17.12, 3.18.6 and 3.19.3.
Published: 2026-03-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of issue and pull request metadata
Action: Immediate Update
AI Analysis

Impact

An improper authorization flaw in GitHub Enterprise Server enables users who have only read access to a repository but write access to a project to alter issue and pull request metadata through the project interface. This weakness, identified as CWE‑639, allows a user to modify metadata such as labels, assignees, or state of issues and pull requests without possessing repository write permissions. The consequence is a privilege escalation that can tamper with the content and workflow of a repository’s issue tracking system.

Affected Systems

GitHub Enterprise Server installations running versions prior to 3.14.24, 3.15.19, 3.16.15, 3.17.12, 3.18.6 or 3.19.3 are affected. The issue originates from the way project item updation is handled: when a project item is added to an existing project, column value changes are applied without verifying that the actor has repository write rights.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating moderate severity, while the EPSS score is below 1%, suggesting low current exploitation probability. It is not listed in the CISA KEV catalog. The attack requires a user who can add items to a project and read the repository. Once such a user adds an item, the system accepts column value updates without permission checks, enabling tampering with issue and pull request metadata. This permission bypass can be leveraged to manipulate project workflows, potentially compromising confidentiality or integrity of repository data.

Generated by OpenCVE AI on April 16, 2026 at 03:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GitHub Enterprise Server to a fixed release (3.14.24 or newer).
  • Reconfigure project write permissions so that only users with repository write access can modify project items.
  • Enable and review audit logs to detect unauthorized changes to issue or pull request metadata.

Generated by OpenCVE AI on April 16, 2026 at 03:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 12 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 11 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Github
Github enterprise Server
Vendors & Products Github
Github enterprise Server

Tue, 10 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Description An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value updates were applied without verifying the actor's repository write permissions. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.24, 3.15.19, 3.16.15, 3.17.12, 3.18.6 and 3.19.3.
Title Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Github Enterprise Server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_P

Published:

Updated: 2026-03-11T14:17:24.504Z

Reserved: 2026-02-26T21:00:40.345Z

Link: CVE-2026-3306

cve-icon Vulnrichment

Updated: 2026-03-11T14:17:18.759Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-10T18:19:01.137

Modified: 2026-03-12T18:46:22.260

Link: CVE-2026-3306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T03:45:16Z

Weaknesses