CVE-2026-5845 — Github Enterprise_server: An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context, which could be chained with token revocation timing and SSH push attribution to obtain and reuse a victim-scope CVSSv3.1 9.6 (CRITICAL) · EPSS 3th percentile