
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76851 is a Server-Side Request Forgery (SSRF) vulnerability in GitHub Enterprise Server (GHES) that enables remote code execution on affected instances. Insufficient network isolation allows malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service, resulting in elevated code execution. The vulnerability affects all GHES versions prior to 3.22, specifically versions 3.17.0–3.17.19, 3.18.0–3.18.13, 3.19.0–3.19.10, 3.20.0–3.20.6, and 3.21.0–3.21.4. It was disclosed on September 1, 2026, and reported via the GitHub Bug Bounty program. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, GHES 3.17 Release Notes).
The root cause is classified as CWE-918 (Server-Side Request Forgery), arising from insufficient network isolation in the GHES pre-receive hook execution environment. When pre-receive hook networking is enabled, hook code running in the hook sandbox can craft requests that impersonate trusted internal services, redirecting those requests to privileged internal endpoints that would not normally be accessible from user-controlled code. This allows the hook to interact with internal services as if it were a trusted component, ultimately achieving elevated code execution on the instance. Exploitation requires two preconditions: pre-receive hook networking must be enabled on the instance, and the attacker must have either site administrator privileges or write access to a repository that has a configured pre-receive hook (GitHub Advisory, GHES 3.18 Release Notes).
Successful exploitation allows an authenticated attacker to execute arbitrary code with elevated privileges on the GitHub Enterprise Server instance. The impact spans all three security dimensions — confidentiality, integrity, and availability — as an attacker with code execution on the server could access sensitive repository data and secrets, modify or destroy data, and disrupt service availability. Given that GHES instances typically host an organization's entire source code, CI/CD pipelines, and associated secrets, a successful compromise could serve as a significant pivot point for lateral movement within an enterprise environment (GitHub Advisory, GHES 3.21 Release Notes).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0044 (0.44%), indicating a low current probability of exploitation in the wild. The NVD SSVC assessment classifies the vulnerability as non-automatable with total technical impact, reflecting the significant damage potential if exploited despite the authentication requirement. No threat actor attribution has been reported.
GitHub has released patched versions addressing CVE-2026-76851: 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5, all released on September 1, 2026. Upgrading to one of these versions (or to 3.22.0 or later) is the primary recommended remediation. As an interim workaround, administrators should disable pre-receive hook networking if it is not required for their use case, which removes the attack surface entirely. Additionally, access to pre-receive hook configuration should be restricted — limit site administrator privileges to trusted personnel and carefully control write access to repositories containing configured pre-receive hooks (GitHub Advisory, GHES 3.20 Release Notes).
The vulnerability was reported through GitHub's Bug Bounty program and disclosed alongside several other HIGH-severity fixes in the September 1, 2026 GHES patch releases. No notable independent researcher commentary, social media discussion, or significant media coverage specific to CVE-2026-76851 has been identified beyond standard vulnerability database aggregation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."