
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1355 is a Missing Authorization vulnerability in GitHub Enterprise Server (GHES) that allows an authenticated attacker to upload unauthorized content to another user's repository migration export. By supplying a known migration identifier to the repository migration upload endpoint — which lacked a proper authorization check — an attacker could overwrite or replace a victim's migration archive, potentially causing victims to download attacker-controlled repository data during migration restores or automated imports. The vulnerability affects all GHES versions prior to 3.20 and was disclosed on February 18, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, GHES 3.14 Release Notes).
The root cause is CWE-862 (Missing Authorization): the repository migration upload endpoint did not verify whether the authenticated requester was authorized to upload content to the migration export identified by the supplied migration identifier. An attacker with any valid authentication to the target GHES instance could craft an HTTP request to the migration upload endpoint, supplying a victim's migration identifier, and overwrite the victim's migration archive with attacker-controlled content. The attack vector is network-based, requires low privileges (any authenticated user), and no user interaction from the attacker's side, though the victim must subsequently perform a migration restore or automated import for the malicious archive to be consumed (Feedly, GHES 3.14 Release Notes).
Successful exploitation primarily affects integrity: an attacker can replace a victim's legitimate repository migration archive with attacker-controlled data, meaning any repository imported from that archive will contain malicious content rather than the intended source. There is no direct confidentiality or availability impact on the server itself, but downstream consequences could include introduction of malicious code, backdoors, or corrupted data into repositories restored from the tampered archive. The scope is limited to the GHES instance and does not affect GitHub.com or GitHub Enterprise Cloud (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-1355. The vulnerability was discovered and responsibly disclosed through the GitHub Bug Bounty program. The EPSS score is approximately 0.094% (very low probability of exploitation in the near term). It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication to the victim's GHES instance and knowledge of the target migration identifier, which limits opportunistic exploitation (Feedly).
migration or upload events associated with mismatched user accounts./api/v3/migrations/.../archive) from authenticated users who are not the migration owner.GitHub has released patched versions addressing CVE-2026-1355 across all supported release series: 3.14.23, 3.15.18, 3.16.14, 3.17.11, 3.18.5, and 3.19.2. All GHES instances running versions prior to these releases should be upgraded immediately. No configuration-based workaround is available; upgrading to a fixed version is the only remediation. Administrators should also review audit logs for any suspicious migration upload activity prior to patching (GHES 3.14 Release Notes, GHES 3.15 Release Notes, GHES 3.16 Release Notes).
The vulnerability was reported through the GitHub Bug Bounty program and disclosed by GitHub in the release notes for the respective patched versions. No significant independent researcher commentary, social media discussion, or notable media coverage has been identified beyond standard vulnerability database entries and aggregator publications (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."