CVE-2026-82282

Source
https://cve.org/CVERecord?id=CVE-2026-82282
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82282.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82282
Published
2026-08-28T16:19:01.750Z
Modified
2026-08-30T03:48:23.664929960Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Atlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated Callers
Details

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook payload forgery.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82282.json",
    "cwe_ids": [
        "CWE-306"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/runatlantis/atlantis

Affected ranges

Type
GIT
Repo
https://github.com/runatlantis/atlantis
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.47.1"
        },
        {
            "fixed": "0.47.1"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.15.1
v0.16.0
v0.16.1
v0.17.0
v0.17.0-beta
v0.17.1
v0.17.2
v0.17.3
v0.17.4
v0.17.5
v0.17.6
v0.18.0
v0.18.1
v0.18.2
v0.18.3
v0.18.4
v0.18.5
v0.19.0
v0.19.1
v0.19.2
v0.19.2-pre.20220408
v0.19.3
v0.19.3-pre.20220408
v0.19.3-pre.20220429
v0.19.4
v0.19.4-pre.20220513
v0.19.5
v0.19.5-pre.20220616
v0.19.5-pre.20220622
v0.19.5-pre.20220628
v0.19.6
v0.19.7
v0.19.7-pre.20220713
v0.19.8
v0.19.8-pre.20220722
v0.19.8-pre.20220810
v0.19.9
v0.19.9-pre.20220822
v0.19.9-pre.20220908
v0.19.9-pre.20220912
v0.19.9-pre.20220923
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.20.0
v0.20.1
v0.20.2-pre.20221106
v0.21.0
v0.21.0-pre.20221114
v0.21.0-pre.20221120
v0.21.0-pre.20221207
v0.21.1-pre.20221213
v0.22.0
v0.22.0-pre.20221219
v0.22.0-pre.20221226
v0.22.1
v0.22.2
v0.22.3
v0.22.3-pre.20230110
v0.22.3-pre.20230111
v0.23.0
v0.23.0-pre.20230125
v0.23.0-pre.20230209
v0.23.0-pre.20230222
v0.23.1
v0.23.2
v0.23.3
v0.23.4
v0.23.5
v0.24.0
v0.24.1
v0.24.2
v0.24.3
v0.24.4
v0.25.0
v0.26.0
v0.28.0
v0.28.2
v0.29.0
v0.3.0
v0.3.1
v0.3.10
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.30.0
v0.31.0
v0.32.0
v0.33.0
v0.34.0
v0.35.0
v0.35.1
v0.36.0
v0.37.0
v0.37.1
v0.38.0
v0.39.0
v0.4.0
v0.4.1
v0.4.10
v0.4.11
v0.4.12
v0.4.13
v0.4.14
v0.4.15
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.40.0
v0.41.0
v0.42.0
v0.43.0
v0.44.0
v0.44.1
v0.45.0
v0.46.0
v0.47.0
v0.5.0
v0.5.1
v0.6.0
v0.7.0
v0.7.1
v0.7.2
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82282.json"