CVE-2026-103620 Overview
CVE-2026-103620 is a missing authorization vulnerability [CWE-862] in GitHub Enterprise Server (GHES). A repository collaborator with write access can delete the current default branch through the GraphQL API. Once deleted, an attacker-controlled branch becomes the new default. In repositories that required pull-request review but did not restrict branch deletion, this behavior bypassed the review requirement. Fresh clones and default-branch API requests then served attacker-controlled content. The flaw was reported through the GitHub Bug Bounty program and affects supported GHES releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series.
Critical Impact
A write-level collaborator can bypass pull-request review controls and replace the default branch, causing downstream clones and CI/CD pipelines to consume attacker-controlled code.
Affected Products
- GitHub Enterprise Server 3.18 (prior to 3.18.16)
- GitHub Enterprise Server 3.19 (prior to 3.19.13)
- GitHub Enterprise Server 3.20 (prior to 3.20.9), 3.21 (prior to 3.21.7), and 3.22 (prior to 3.22.2)
Discovery Timeline
- 2026-10-06 - CVE-2026-103620 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-103620
Vulnerability Analysis
The vulnerability resides in the authorization logic of the GraphQL API handling branch deletion on GitHub Enterprise Server. Branch protection rules were not consistently enforced when a default branch deletion was requested through GraphQL. A collaborator with write access could remove the designated default branch even when pull-request review was mandated for changes to that branch. After deletion, GHES automatically promoted another branch to default status, allowing an attacker to pre-stage a branch containing malicious commits and have it become the new baseline.
Downstream consumers were affected without any direct code push to the protected branch. Fresh clones, default-branch API queries, and automation that resolved HEAD all began serving the attacker-controlled branch contents. This turns a repository-level authorization gap into a supply-chain integrity issue.
Root Cause
The root cause is a missing authorization check [CWE-862] in the GraphQL mutation path for branch deletion. The server did not verify that branch protection or deletion-restriction policies applied before honoring the delete request on the default branch. Pull-request review requirements were enforced for pushes but not for the delete-and-replace sequence that effectively rewrote the default pointer.
Attack Vector
Exploitation requires network access to the GHES GraphQL endpoint and valid credentials for a repository collaborator with write permission. The attacker first pushes an attacker-controlled branch to the target repository. The attacker then issues a GraphQL mutation to delete the current default branch. GHES promotes the attacker's branch to default. Subsequent clones, release automation, and main-tracking consumers ingest the malicious content. See the vendor release notes for additional technical context: GitHub Enterprise Release Notes 3.22.2.
Detection Methods for CVE-2026-103620
Indicators of Compromise
- Audit log entries recording protected_branch.destroy or branch deletion events targeting the default branch of a repository.
- GraphQL requests invoking the deleteRef mutation against refs/heads/<default-branch> from non-administrative accounts.
- Default branch name changes immediately followed by CI/CD pipeline runs sourced from a newly promoted branch.
Detection Strategies
- Correlate GHES audit log events for branch deletion with subsequent repo.default_branch change events on the same repository within a short window.
- Alert on GraphQL API traffic where the mutation body contains deleteRef and the target ref matches a tracked default branch.
- Compare commit SHAs resolved for HEAD across clones over time and flag unexpected baseline rewrites.
Monitoring Recommendations
- Forward GHES audit logs and GraphQL access logs to a centralized SIEM and retain them for forensic review.
- Monitor repositories classified as high-value (release, infrastructure, deployment keys) for any default branch mutations.
- Review collaborator permission inventories regularly and remove unused write access to limit exploitation surface.
How to Mitigate CVE-2026-103620
Immediate Actions Required
- Upgrade GitHub Enterprise Server to the fixed release matching your deployed branch: 3.18.16, 3.19.13, 3.20.9, 3.21.7, or 3.22.2.
- Audit recent branch deletion and default-branch change events across all repositories and validate that current default branches contain expected commits.
- Rotate secrets and re-run security scans on any repository where an unexpected default branch change is detected.
Patch Information
GitHub resolved CVE-2026-103620 by enforcing branch protection and deletion-restriction policies on the GraphQL default-branch delete path. Patched versions are available in GHES 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2. Refer to the vendor release notes: GHES 3.18.16, GHES 3.19.13, GHES 3.20.9, GHES 3.21.7, and GHES 3.22.2.
Workarounds
- Enable the "Restrict deletions" branch protection rule on the default branch of every repository so that only administrators can delete it.
- Reduce the number of collaborators granted write access and require elevated roles for repositories that drive production deployments.
- Pin CI/CD pipelines and release automation to specific commit SHAs or signed tags rather than resolving the default branch at build time.
# Enable deletion restriction on the default branch via the GitHub REST API
curl -X PUT \
-H "Authorization: Bearer $GITHUB_TOKEN" \
-H "Accept: application/vnd.github+json" \
https://ghes.example.com/api/v3/repos/ORG/REPO/branches/main/protection \
-d '{
"required_pull_request_reviews": {"required_approving_review_count": 1},
"enforce_admins": true,
"restrictions": null,
"allow_deletions": false,
"required_status_checks": null
}'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.