CVE-2026-82282

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook payload forgery.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 20:20

Updated : 2026-08-31 19:17


NVD link : CVE-2026-82282

Mitre link : CVE-2026-82282

CVE.ORG link : CVE-2026-82282


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function