
‼️ CVE-2026-3306 (CVSS 4.3) GitHub Enterprise Server improper auth—repo read + project write = PR metadata mods. Bug bounty find, patched 3.19.3+. https://app.opencve.io/cve/?vendor=github
Post summary
CVE‑2026‑3306 is an improper authorization issue in GitHub Enterprise Server with a CVSS 4.3 score, now patched in version 3.19.3+, with no evidence of active exploitation or PoC.


