GitHub fixes secret-scanning flaw that can reach code execution on GHES
EditorialBy TrustList Editorial
Exploiting the high-severity bug needs only push access to a repository with Advanced Security on, and a second, medium flaw lets a collaborator swap a repository's default branch.
- Cybersecurity
- Vulnerability Management
- Source Code Management Software
- DevOps
About GitHub fixes secret-scanning flaw that can reach code execution on GHES
GitHub fixes secret-scanning flaw that can reach code execution on GHES
6 October 2026: GitHub has patched CVE-2026-96890, a high-severity server-side request forgery in the secret-scanning validity checks of GitHub Enterprise Server that can lead to remote code execution on the appliance. A second flaw, CVE-2026-103620, rated medium, lets a repository collaborator replace the default branch. Fixes shipped in the 3.22.2 and 3.21.7 releases, and the second flaw is also fixed in 3.18.16. GitHub's notes do not describe exploitation in the wild.
Not yet independently verified. We read the release notes for 3.22.2, 3.21.7 and 3.18.16 only. The notes for 3.19.13 and 3.20.9 were not read, so which fix lands in which of those two is taken from the Hong Kong CERT summary. We will update this when it can be confirmed, and remove this note.
How the high-severity flaw works
An attacker commits crafted GCP service account credentials to a repository. When secret scanning runs its validity check on them, the appliance sends requests to addresses the attacker chose, without enough validation. GitHub says this could lead to remote code execution on the appliance. The attacker needs push access to a repository that has GitHub Advanced Security enabled, so the exposure sits with organisations that give many contributors push rights and have switched secret scanning on.
The default-branch bypass
CVE-2026-103620 involves the GraphQL API. A collaborator with write access could delete the default branch and make a branch under their control the new default. In repositories that require pull request review but do not restrict branch deletion, this skipped the review requirement, so fresh clones and default-branch API requests would receive the attacker's content. GitHub's 3.18.16 notes say the report came through its bug bounty programme.
Fixed versions
Hong Kong's CERT lists the fixed releases as:
- 3.22.2
- 3.21.7
- 3.20.9
- 3.19.13
- 3.18.16
The 3.22.2 and 3.21.7 notes list both CVEs. The 3.18.16 notes list one security fix, CVE-2026-103620. All the releases are dated 6 October.
Before upgrading
GitHub's known issues for these releases include custom firewall rules being removed during an upgrade, so they must be reapplied afterwards. The 3.18.16 notes also mention that Management Console lockouts do not unlock on their own and need SSH access to clear. Until a patch is in, restricting who can push to repositories with Advanced Security enabled, and restricting branch deletion where review rules matter, narrows both paths.
Company profile on TrustList: GitHub
Related on TrustList:
- GitLab AI Gateway flaw CVE-2026-90970 lets Duo Agent Platform users escape the sandbox and run commands: update self-hosted gateways
- GitHub Enterprise Cloud with data residency refuses X25519-only TLS clients from 7 October 2026
Sources
- GitHub Docs, GitHub Enterprise Server 3.22.2 release notes, 6 October 2026
- GitHub Docs, GitHub Enterprise Server 3.21.7 release notes, 6 October 2026
- GitHub Docs, GitHub Enterprise Server 3.18.16 release notes, 6 October 2026
- HKCERT, GitHub Enterprise Server Multiple Vulnerabilities, 8 October 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Source Code Management Software
- DevOps
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.