PatchSiren cyber security CVE debrief
CVE-2026-76851 GitHub CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server, allowing remote code execution on the instance due to insufficient network isolation and exploitation of pre-receive hook code. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. The CVE record was published on 2026-09-01T22:17:13.033Z and has not been modified since then. Organizations should review their configurations and apply patches to prevent potential code execution.
- Vendor
- GitHub
- Product
- Enterprise Server
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-03
Who should care
Organizations using GitHub Enterprise Server, particularly those with pre-receive hook networking enabled, should prioritize patching to prevent potential code execution. This includes reviewing and restricting pre-receive hook networking configurations, limiting site administrator privileges and repository write access, and monitoring for suspicious activity related to pre-receive hooks. Additionally, organizations should assess their current configurations and ensure that they are not exposed to this vulnerability by reviewing their network isolation and pre-receive hook code for potential weaknesses or malicious activity that could be exploited for elevated code execution. Those with write access to a repository containing a configured pre-receive hook or site administrator privileges are at higher risk and should take immediate action to secure their environments. Furthermore, organizations should verify that their instances are updated to a patched version and consider implementing compensating controls for exposed systems while remediation is scheduled and verified. Regular monitoring and detection of suspicious activity related to pre-receive hooks can help mitigate potential threats until patches are applied. Asset inventory and configuration reviews are also recommended to ensure that all instances are accounted for and properly secured. This vulnerability's impact extends to operators, platform administrators, vulnerability management teams, and security teams, all of whom should be aware of the potential risks and take appropriate measures to protect their environments. By taking these steps, organizations can reduce their risk exposure and protect against potential exploitation of this SSRF vulnerability in GitHub Enterprise Server. Regular review of official advisories and CVE records is also crucial for staying informed about the latest developments and recommended actions. Lastly, tracking exceptions, retesting remediated assets, and documenting evidence are essential for closing the item only after thorough verification of remediation efforts. Therefore, a comprehensive approach that includes patching, configuration review, access control, and on
Technical summary
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server, allowing remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service, leading to elevated code execution. Exploitation required pre-receive hook networking to be enabled and either site administrator privileges or write access to a repository containing a configured pre-receive hook. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5.
Defensive priority
Organizations using GitHub Enterprise Server should prioritize patching to prevent potential code execution.
Recommended defensive actions
- Apply patches to GitHub Enterprise Server instances to prevent exploitation
- Review and restrict pre-receive hook networking configurations
- Limit site administrator privileges and repository write access
- Monitor for suspicious activity related to pre-receive hooks
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE-2026-76851 vulnerability was reported via the GitHub Bug Bounty program. A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server, allowing remote code execution on the instance due to insufficient network isolation and exploitation of pre-receive hook code.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76851 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76851
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76851 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76851
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
-
Source reference
Unverified legacy reference
URL: https://docs.github.com/en/[email protected]/admin/release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.