Identity & Access

Critical Authentication Flaw Haunts GitHub Enterprise Server

GitHub patches a trio of security defects in the GitHub Enterprise Server product and recommends urgent patching for corporate users.

GitHub vulnerability

GitHub has released an urgent fix for a trio of security defects in the GitHub Enterprise Server product and warned that hackers can exploit one of the flaws to gain site administrator privileges.

The most severe issue is tracked as CVE-2024-6800 and covers a vulnerability that allows an attacker to manipulate SAML SSO authentication to provision and/or gain access to a user account with site administrator privileges.

The vulnerability carries a CVSS severity score of 9.5/10 and is described as an XML signature wrapping bug in GitHub Enterprise Server (GHES) when utilizing SAML authentication with specific identity providers.

“This vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication,” according to the advisory. 

GitHub said the vulnerability, reported privately via its bug bounty program, affects all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. 

The company also documented a pair of medium-severity flaws that allow attackers to update the title, assignees, and labels of any issue inside a public repository; and disclose the issue contents from a private repository using a GitHub App with only contents: read and pull requests: write permissions. 

Advertisement. Scroll to continue reading.

GitHub Enterprise Server is the self-hosted version of GitHub Enterprise. It is installed on-prem or on a private cloud and provides  features of the cloud-based version of GitHub, including pull requests, code reviews, and project management tools.

Related: Critical Authentication Bypass Resolved in GitHub Enterprise Server

Related: GitHub Enterprise Server Gets New Security Capabilities

Related: Serious Vulnerability in GitHub Enterprise Earns Researcher $20,000

Related: Hackers Earn Big Bounties for GitHub Enterprise Flaw

Related Content

Vulnerabilities

A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance.

Application Security

Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.

Data Breaches

The TeamPCP hacking group accessed the repositories after a GitHub employee installed a poisoned VS Code extension.

Vulnerabilities

The remote code execution flaw CVE-2026-3854 was found to impact GitHub.com and GitHub Enterprise Server.

Artificial Intelligence

Researchers found an OpenAI Codex vulnerability that could have been exploited to compromise GitHub tokens.

Supply Chain Security

Hackers published a malicious scanner release and replaced tags to point to information-stealer malware.

Malware & Threats

Hundreds of GitHub accounts were accessed using credentials stolen in the VS Code GlassWorm campaign.

Vulnerabilities

Attackers can inject malicious instructions in a GitHub Issue that are automatically processed by Copilot when launching a Codespace from that issue.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version