CVE-2026-103504EPSS p16.2%

CVE-2026-103504CVE-2026-103504

Description

Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.

Scoring

CVSS 8.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS0.26% probability of exploitation · percentile 16.2% · 2026-10-10T12:00:23Z
Last modified2026-10-07
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.