CVE Explorer
CVE-2026-6736
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When external authentication was enabled, the signup endpoint did not properly enforce the authentication restriction, allowing account creation and session establishment without identity provider validation. The created account was limited to the default base permissions configured on the i
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"affected","product":"Enterprise Server","vendor":"GitHub","versions":[{"changes":[{"at":"3.16.18","status":"unaffected"}],"lessThanOrEqual":"3.16.17","status":"affected","version":"3.16.0","versionType":"semver"},{"changes":[{"at":"3.17.15","status":"unaffected"}],"lessThanOrEqual":"3.17.14","status":"affected","version":"3.17.0","versionType":"semver"},{"changes":[{"at":"3.18.9","status":"unaffected"}],"lessThanOrEqual":"3.18.8","status":"affected","version":"3.18.0","versionType":"semver"},{"changes":[{"at":"3.19.6","status":"unaffected"}],"lessThanOrEqual":"3.19.5","status…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpa…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"tags":["release-notes"],"url":"https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.18"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/references/0
{"tags":["release-notes"],"url":"https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.15"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/references/1
{"tags":["release-notes"],"url":"https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/references/2
{"tags":["release-notes"],"url":"https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/references/3
{"tags":["release-notes"],"url":"https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7f32cafd9c3d006a926265ccad7b6dc6ace56e556de64cb1e48261b98d39cc2 · sha256:fdd1245cb83cf8cc… · /containers/cna/references/4
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.