Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-9132

Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
30/06/2026
Última modificación:
02/07/2026

Descripción

*** Pendiente de traducción *** A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The<br /> Copilot pull request description diff summary endpoint accepted a cross-repository comparison range and rendered the resulting diff without verifying that the requesting user was authorized to view<br /> the target repository. Exploitation required an authenticated account on the instance with read access to at least one repository to use as the comparison base. This vulnerability affected all<br /> versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.17.17, 3.18.11, 3.19.8, and 3.20.4. This vulnerability was reported via the GitHub Bug Bounty program.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* 3.17.17 (excluyendo)
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* 3.18.0 (incluyendo) 3.18.11 (excluyendo)
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* 3.19.0 (incluyendo) 3.19.8 (excluyendo)
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:* 3.20.0 (incluyendo) 3.20.4 (excluyendo)