---
id: CVE-2026-103620
title: >-
  A missing authorization vulnerability was identified in GitHub Enterprise
  Server that allowed a repository collaborator with write access to delete the
  current default branch through the GraphQL API and cause an
  attacker-controlled branc…
summary: >-
  A missing authorization vulnerability was identified in GitHub Enterprise
  Server that allowed a repository collaborator with write access to delete the
  current default branch through the GraphQL API and cause an
  attacker-controlled branc…
severity: medium
cvss: 6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-862
vendor: GitHub
product: Enterprise Server
affected:
  - enterprise_server >= 3.18.0 < 3.18.*
  - enterprise_server >= 3.19.0 < 3.19.*
  - enterprise_server >= 3.20.0 < 3.20.*
  - enterprise_server >= 3.21.0 < 3.21.*
  - enterprise_server >= 3.22.0 < 3.22.*
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:03:40.690'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103620'
references:
  - url: >-
      https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.16
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.13
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.9
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.7
    label: product-cna@github.com
  - url: >-
      https://docs.github.com/en/enterprise-server@3.22/admin/release-notes#3.22.2
    label: product-cna@github.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-06T19:13:33.850Z'
---

## Overview

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but did not restrict branch deletion, this bypassed the review requirement and caused fresh clones and default-branch API requests to use attacker-controlled content. This vulnerability affected supported GitHub Enterprise Server releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported via the GitHub Bug Bounty program.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
