OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-103504 (CVSS 8.1)

NVD · officialPublished Oct 6, 2026Risk 37/100EPSS 0.2%

Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.

CVSS
8.1
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source