What is CVE-2026-17556?
CVE-2026-17556 is a path traversal vulnerability in GitHub Enterprise Server that allows an unauthenticated attacker to delete arbitrary files and directories, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. This poses a critical risk of complete data loss and requires immediate patching.
Azərbaycanca: CVE-2026-17556, GitHub Enterprise Server-də autentifikasiya olunmamış hücumçuya path traversal vasitəsilə Git LFS obyektləri, buraxılış faylları və istifadəçi avatarları kimi kritik istifadəçi məlumatlarını ehtiva edən ixtiyari fayl və qovluqları silməyə imkan verən boşluqdur. Bu zəiflik tam məlumat itkisinə səbəb ola bilər, ona görə də dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What operation can an attacker perform using CVE-2026-17556 in GitHub Enterprise Server?
An unauthenticated attacker can delete arbitrary files and directories, including critical user data such as Git LFS objects, release assets, attachments, and avatars, via path traversal.
What is the most severe consequence if CVE-2026-17556 is exploited?
This vulnerability can lead to complete data loss.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.