CVE-2026-9106
MEDIUMGitHub Enterprise Server < 3.22 - OAuth Consent Runner Scope Misrepresentation
Title source: manualDescription
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
References (6)
Core 6
Core References
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.19.8
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.20.4
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.21.2
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.17.17
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.18.11
Release Notes release-notes
https://docs.github.com/en/[email protected]/admin/release-notes#3.16.20
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
11.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-451
Status
published
Products (7)
GitHub/Enterprise Server
3.16.0 - 3.16.19
GitHub/Enterprise Server
3.17.0 - 3.17.16
GitHub/Enterprise Server
3.18.0 - 3.18.10
GitHub/Enterprise Server
3.19.0 - 3.19.7
GitHub/Enterprise Server
3.20.0 - 3.20.3
GitHub/Enterprise Server
3.21.0 - 3.21.1
github/enterprise_server
< 3.16.20
Published
Jun 30, 2026
Tracked Since
Jul 01, 2026