
Found a fascinating bug bounty disclosure in GitHub Enterprise this week. A Personal Access Token that didn't have the repo scope could still retrieve issues and commits from private repositories via search API endpoints. The flaw (CVE-2026-3582) required the attacker to already have legitimate repository access through organisation membership, but it highlights a common problem: token scopes are only as good as the backend code that enforces them. Key lesson for bug bounty hunters: test scope boundaries early and often. Sometimes the permission model has gaps that aren't obvious from the documentation.
Post summary
GitHub Enterprise bug (CVE‑2026‑3582) allows repo‑scope‑restricted tokens to read private repo data via the search API, revealing a scope enforcement flaw; no PoC, exploit code, active threat, or patch discussed.


