CVE-2026-8106Disclosure(github / enterprise_server)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form element that could capture administrator credentials. Exploitation required an administrator to click a crafted link and enter their credentials. This vulnerability affected GitHub Enterprise Server versions 3.19.1 through 3.19.5 and 3.20.0 through 3.20.1, and was fixed in versions 3.19.6 and 3.20.2. This vulnerability was reported via the GitHub Bug Bounty program.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_server

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_server

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-08: 1Mentions · 2026-05-10: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-10: 105-0805-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8106 A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to… https://www.cve.org/CVERecord?id=CVE-2026-8106

    Post summary

    The text announces CVE‑2026‑8106 as a reflected HTML injection issue in GitHub Enterprise Server’s login page, potentially enabling credential theft, with no mention of PoC, exploitation, or patches.

    00000202
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8106 Reflected HTML Injection in GitHub Enterprise Server Management Console Login Page https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8106

    Post summary

    The text announces CVE‑2026‑8106 as a reflected HTML injection flaw in the GitHub Enterprise Server Management Console login page, providing only a brief description without further technical details, PoC, exploitation evidence, or remediation information.

    0000060
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgithubenterprise_server---

Explore more