CVE-2026-103504

CVE-2026-103504 is a security vulnerability that is still awaiting full analysis and scoring. The underlying weakness is classified as CWE-272.

Key facts

Description

Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.

Frequently asked questions

What is CVE-2026-103504?
Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.
Is CVE-2026-103504 being actively exploited?
It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
How do I fix CVE-2026-103504?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
When was CVE-2026-103504 published?
CVE-2026-103504 was published on 2026-10-06.

References

Other CWE-272 vulnerabilities

Browse all CWE-272 vulnerabilities →