CVE-2026-9106: UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the managerunners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.
Other sources
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the managerunners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17. This vulnerability was reported via the GitHub Bug Bounty program.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.17.17Patch 3.17.17 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.18.11Patch 3.18.11 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.19.8Patch 3.19.8 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.20.4Patch 3.20.4 - Upgrade
Upgrade
GitHub Enterprise Serverto a version that resolves this vulnerability.Fixed in 3.21.2Patch 3.21.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9106?
CVE-2026-9106 has a medium severity rating of 4.8 according to CVSS.
How do I fix CVE-2026-9106?
To mitigate CVE-2026-9106, users should update their GitHub Enterprise Server to the latest version where the vulnerability is addressed.
What does CVE-2026-9106 exploit?
CVE-2026-9106 exploits a UI misrepresentation vulnerability that allows unauthorized organization runner management.
Who is affected by CVE-2026-9106?
CVE-2026-9106 affects users of GitHub Enterprise Server who use OAuth applications requesting the manage_runners:org scope.
What is the risk of not addressing CVE-2026-9106?
Failing to address CVE-2026-9106 may allow attackers to gain unauthorized access to manage organization runners.