CVE-2026-75101 Overview
CVE-2026-75101 is an authorization bypass vulnerability in GitHub Enterprise Server that lets any authenticated user read raw diffs and patches of pull requests in private repositories. The flaw stems from how access tokens for raw pull request diffs and patches were scoped. Tokens were bound to the repository name and pull request number rather than to a globally unique repository identifier. An attacker who created their own repository and pull request matching the target's naming could reuse their token to fetch a private pull request's contents. Exploitation required knowledge of the target repository name and a valid pull request number. GitHub fixed the flaw in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6.
Critical Impact
Any authenticated user on a vulnerable GitHub Enterprise Server instance could exfiltrate source code changes from private pull requests, exposing proprietary code, credentials, and unreleased fixes.
Affected Products
- GitHub Enterprise Server versions prior to 3.17.21
- GitHub Enterprise Server 3.18.x prior to 3.18.15, 3.19.x prior to 3.19.12, and 3.20.x prior to 3.20.8
- GitHub Enterprise Server 3.21.x prior to 3.21.6
Discovery Timeline
- 2026-09-22 - CVE-2026-75101 published to NVD
- 2026-09-23 - Last updated in NVD database
- Vulnerability was reported via the GitHub Bug Bounty program
Technical Details for CVE-2026-75101
Vulnerability Analysis
The vulnerability is an authorization bypass classified as [CWE-639] Authorization Bypass Through User-Controlled Key. GitHub Enterprise Server issues short-lived tokens that authorize downloads of raw pull request diffs and patches. The server validated these tokens against the repository name and pull request number provided in the request. It did not verify that the token belonged to the same globally unique repository object being accessed. An attacker with an account on the instance could exploit this identifier collision to read private repository content.
The EPSS score of 0.449% reflects the current probability of exploitation activity being observed. Exploitation does not require administrative privileges, only a low-privileged authenticated account and reconnaissance of the target repository name and pull request number.
Root Cause
The root cause is improper object binding in the token authorization check. Access tokens should reference a repository by an internal immutable identifier such as a numeric database ID. Instead, tokens were scoped to a (repository_name, pull_request_number) tuple, which is not unique across the instance. Two different repositories on the same server could share the same name and pull request number, allowing token reuse across security boundaries.
Attack Vector
An attacker with any account on the GitHub Enterprise Server instance performs the following steps. First, the attacker identifies a target private repository and a valid pull request number, either through prior knowledge, leaked references, or enumeration. Second, the attacker creates a repository under their own account using the same name as the target. Third, the attacker opens pull requests until the numbering aligns with the target pull request number. Finally, the attacker requests a raw diff or patch access token for their own repository and uses it against the target repository path. The server accepts the token because the name and number match, returning the private diff content.
No verified public exploit code is available for CVE-2026-75101. See the GitHub Enterprise Server release notes for vendor-provided technical details.
Detection Methods for CVE-2026-75101
Indicators of Compromise
- Requests to raw pull request diff or patch endpoints where the authenticated user has no membership or collaborator role in the target repository
- Unusual volume of newly created repositories with names matching existing private repositories on the instance
- Repeated pull request creation on newly created repositories that appears designed to advance the pull request counter
Detection Strategies
- Audit GitHub Enterprise Server access logs for GET requests to .diff and .patch endpoints on private repositories and correlate the requesting user against repository access grants
- Alert on token issuance events where a raw diff or patch token is subsequently used against a repository owned by a different user or organization
- Baseline repository creation patterns per user and flag accounts that create many repositories with names duplicating those of private repositories
Monitoring Recommendations
- Forward GitHub Enterprise Server audit logs and web request logs to a centralized analytics platform for retrospective hunting
- Monitor for reconnaissance patterns such as sequential requests to pull request numbers on private repositories from unauthorized users
- Review outbound traffic from user accounts that show anomalous read patterns against pull request APIs
How to Mitigate CVE-2026-75101
Immediate Actions Required
- Upgrade GitHub Enterprise Server to 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, or later within your maintenance window
- Review audit logs for suspicious access to .diff and .patch endpoints from accounts without legitimate repository access
- Rotate any secrets, tokens, or credentials that may have been present in private pull request diffs during the exposure window
Patch Information
GitHub released fixes across five supported branches. Administrators should apply the patch corresponding to their deployed branch: 3.17.21, 3.18.15, 3.19.12, 3.20.8, or 3.21.6. All versions prior to 3.22 were affected before these fixes.
Workarounds
- No vendor-supplied workaround exists; upgrading to a patched release is the only supported remediation
- Restrict instance access to trusted users only until the patch is applied to reduce the pool of accounts that could exploit the flaw
- Increase monitoring of pull request diff and patch endpoint access to identify unauthorized retrieval attempts in the interim
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.