CVE-2026-9106
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management.
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-451
- Affected
- github/enterprise server
- Source
- product-cna@github.com
References
- https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.20Release Notes
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.17Release Notes
- https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.11Release Notes
- https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.8Release Notes
- https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.4Release Notes
- https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.2Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.