CVE-2026-82282 HIGH

CVE-2026-82282: Atlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated Callers

Vendor Runatlantis
Product atlantis
Weakness CWE-306 · Missing auth
Published August 28, 2026
Last update August 28, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

What the vulnerability does

01Description

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook payload forgery.

Key dates

02Disclosure timeline

August 28, 2026 CVE published

Related vulnerabilities

04Related CVE