
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3306 is an improper authorization vulnerability in GitHub Enterprise Server (GHES) that allows a user with read access to a repository and write access to a project to modify issue and pull request metadata — including labels, assignees, and other fields — without possessing repository write permissions. The flaw exists because when adding a duplicate item to a project, column value updates were applied without verifying the actor's repository write permissions. It affects GHES versions prior to 3.14.24, 3.15.19, 3.16.15, 3.17.12, 3.18.6, and 3.19.3. The vulnerability was disclosed on March 10, 2026, reported via the GitHub Bug Bounty program, and carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub GHES 3.14 Release Notes, Feedly).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), with an estimated classification of CWE-862 (Missing Authorization). The vulnerability resides in the GitHub Projects feature: when a user adds an item to a project that already exists (a duplicate item), the server applies column value updates — such as label or assignee changes — to the underlying issue or pull request without re-verifying that the actor holds write permissions on the associated repository. This means the authorization check is bypassed by exploiting the duplicate-item code path, allowing a low-privileged user (read-only on the repo, write on the project) to tamper with repository metadata. The attack is network-based, requires low privileges, no user interaction, and low complexity (GitHub GHES 3.14 Release Notes, Feedly).
Successful exploitation allows an attacker to modify issue and pull request metadata — including labels, assignees, milestones, and other project column values — on repositories for which they only hold read access. The impact is limited to integrity: there is no confidentiality or availability impact, and the scope is unchanged. While this does not enable code execution or data exfiltration, it could be used to manipulate project tracking, mislabel security-sensitive issues, or interfere with development workflows in enterprise environments (GitHub GHES 3.14 Release Notes, Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-3306. The EPSS score is approximately 0.035% (0.000350), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated user account with at minimum read access to a target repository and write access to a project containing items from that repository, limiting the attacker pool to internal or invited users on a GHES instance (Feedly).
project.add_item or equivalent events) by users who do not hold write permissions on the associated repository, particularly where the same issue/PR ID appears added multiple times in quick succession.addProjectV2ItemById or REST project item endpoints) from accounts that lack repository write access, followed immediately by field update mutations.GitHub has released patched versions of GitHub Enterprise Server that address this vulnerability. Administrators should upgrade to one of the following fixed releases as soon as possible: 3.14.24 (note: initially unpublished due to a separate Git version mismatch; use 3.14.25 or later), 3.15.19 (similarly unpublished; use 3.15.20 or later), 3.16.15, 3.17.12, 3.18.6, or 3.19.3. No configuration-based workaround is available; upgrading is the only remediation. GitHub Cloud (GitHub.com) is not affected (GitHub GHES 3.14 Release Notes, GitHub GHES 3.15 Release Notes, GitHub GHES 3.16 Release Notes, GitHub GHES 3.17 Release Notes, GitHub GHES 3.18 Release Notes).
The vulnerability was reported through GitHub's Bug Bounty program and received limited public attention given its medium severity and constrained exploitation prerequisites. Automated CVE tracking services such as CVEFeed, VulDB, and Radar/Offseq indexed the vulnerability shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond standard CVE aggregation (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."