CVE-2026-1355: 
GitHub Enterprise Server vulnerability analysis and mitigation

Overview

CVE-2026-1355 is a Missing Authorization vulnerability in GitHub Enterprise Server (GHES) that allows an authenticated attacker to upload unauthorized content to another user's repository migration export. By supplying a known migration identifier to the repository migration upload endpoint — which lacked a proper authorization check — an attacker could overwrite or replace a victim's migration archive, potentially causing victims to download attacker-controlled repository data during migration restores or automated imports. The vulnerability affects all GHES versions prior to 3.20 and was disclosed on February 18, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, GHES 3.14 Release Notes).

Technical details

The root cause is CWE-862 (Missing Authorization): the repository migration upload endpoint did not verify whether the authenticated requester was authorized to upload content to the migration export identified by the supplied migration identifier. An attacker with any valid authentication to the target GHES instance could craft an HTTP request to the migration upload endpoint, supplying a victim's migration identifier, and overwrite the victim's migration archive with attacker-controlled content. The attack vector is network-based, requires low privileges (any authenticated user), and no user interaction from the attacker's side, though the victim must subsequently perform a migration restore or automated import for the malicious archive to be consumed (Feedly, GHES 3.14 Release Notes).

Impact

Successful exploitation primarily affects integrity: an attacker can replace a victim's legitimate repository migration archive with attacker-controlled data, meaning any repository imported from that archive will contain malicious content rather than the intended source. There is no direct confidentiality or availability impact on the server itself, but downstream consequences could include introduction of malicious code, backdoors, or corrupted data into repositories restored from the tampered archive. The scope is limited to the GHES instance and does not affect GitHub.com or GitHub Enterprise Cloud (Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-1355. The vulnerability was discovered and responsibly disclosed through the GitHub Bug Bounty program. The EPSS score is approximately 0.094% (very low probability of exploitation in the near term). It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication to the victim's GHES instance and knowledge of the target migration identifier, which limits opportunistic exploitation (Feedly).

Exploitation steps

  1. Obtain authentication: Acquire valid credentials or a personal access token for the target GitHub Enterprise Server instance (any authenticated user account suffices).
  2. Identify a target migration: Determine or enumerate a migration identifier belonging to another user's in-progress or pending repository migration export. Migration identifiers may be discoverable through API responses, error messages, or timing-based enumeration.
  3. Craft a malicious archive: Prepare a repository migration archive (tarball) containing attacker-controlled content, such as malicious scripts, backdoored code, or corrupted data.
  4. Upload to the migration endpoint: Send an authenticated HTTP request to the repository migration upload endpoint, supplying the victim's migration identifier and the malicious archive as the payload, bypassing the missing authorization check.
  5. Wait for victim to restore: The victim's migration archive is now replaced. When the victim (or an automated process) performs a migration restore or import using that identifier, they will receive and potentially deploy the attacker-controlled repository data (Feedly, GHES 3.14 Release Notes).

Indicators of compromise

  • Logs: GHES audit logs showing unexpected or unauthorized API calls to the repository migration upload endpoint from users who do not own the referenced migration identifier; look for migration or upload events associated with mismatched user accounts.
  • Network: Unusual HTTP PUT/POST requests to migration upload API endpoints (e.g., /api/v3/migrations/.../archive) from authenticated users who are not the migration owner.
  • File System: Unexpected or recently modified migration archive files in the GHES migration storage area that do not correspond to the owning user's activity.
  • Behavioral: Users reporting that restored repositories contain unexpected, unfamiliar, or malicious content not matching their original source repository.

Mitigation and workarounds

GitHub has released patched versions addressing CVE-2026-1355 across all supported release series: 3.14.23, 3.15.18, 3.16.14, 3.17.11, 3.18.5, and 3.19.2. All GHES instances running versions prior to these releases should be upgraded immediately. No configuration-based workaround is available; upgrading to a fixed version is the only remediation. Administrators should also review audit logs for any suspicious migration upload activity prior to patching (GHES 3.14 Release Notes, GHES 3.15 Release Notes, GHES 3.16 Release Notes).

Community reactions

The vulnerability was reported through the GitHub Bug Bounty program and disclosed by GitHub in the release notes for the respective patched versions. No significant independent researcher commentary, social media discussion, or notable media coverage has been identified beyond standard vulnerability database entries and aggregator publications (Feedly).

Additional resources


Source: This report was generated using AI

Related GitHub Enterprise Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77987CRITICAL9.3
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-76851HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-19118HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-77912HIGH7.4
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-75101MEDIUM6
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management