CVE-2026-9132Disclosure(github / enterprise_server)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The Copilot pull request description diff summary endpoint accepted a cross-repository comparison range and rendered the resulting diff without verifying that the requesting user was authorized to view the target repository. Exploitation required an authenticated account on the instance with read access to at least one repository to use as the comparison base. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.17.17, 3.18.11, 3.19.8, and 3.20.4. This vulnerability was reported via the GitHub Bug Bounty program.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_server

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-09: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-09: 106-3007-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-091
Disclosure1
Full discourse3 posts
  • Seokchan Yoon / 윤석찬@_seokchan_yoon
    Disclosure

    two vulnerabilities I reported to @github have been released! 🎉 - CVE-2026-9132 (Missing authorization to private repo disclosure) - CVE-2026-10585 (Stored XSS) https://t.co/1ZyQn6Llc9

    Post summary

    The author announces that two GitHub vulnerabilities (CVE-2026‑9132 and CVE-2026‑10585) have been released, providing brief technical descriptions of each.

    20069104.8K
    810 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9132 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they d… https://www.cve.org/CVERecord?id=CVE-2026-9132 ----- Traducción: CVE-2026-9132 Se … http://infoflow.cloud`

    Post summary

    CVE‑2026‑9132 is a missing‑authorization vulnerability in GitHub Enterprise Server that permits authenticated users to read code from private repositories; the post gives no evidence of exploitation, fixes, or proof of concept.

    0000035
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9132 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they d… https://www.cve.org/CVERecord?id=CVE-2026-9132

    Post summary

    GitHub Enterprise Server has a missing‑authorization flaw (CVE‑2026‑9132) that permits authenticated users to read private repository source code; no evidence of exploitation or patch information is presented.

    00000625
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---

Explore more