CVE-2026-8106
Last modified
CVE-2026-8106 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form element that could capture administrator credentials. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form element that could capture administrator credentials. Exploitation required an administrator to click a crafted link and enter their credentials. This vulnerability affected GitHub Enterprise Server versions 3.19.1 through 3.19.5 and 3.20.0 through 3.20.1, and was fixed in versions 3.19.6 and 3.20.2. This vulnerability was reported via the GitHub Bug Bounty program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Github | Enterprise Server | >= 3.19.1, < 3.19.6 |
| Github | Enterprise Server | >= 3.20.0, < 3.20.2 |
References
- https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.6Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.2Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-8106?
How severe is CVE-2026-8106?
How do I fix CVE-2026-8106?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81036Stalwart Mail Server does not compare an OAuth redirect targ…8.1
- CVE-2026-81046Dell ThinOS 10, versions prior to 2605_10.2616, contain a Pr…9.4
- CVE-2026-81048Dell ThinOS 10, versions prior to 2605_10.2616, contain an I…8.8
- CVE-2026-81049Dell ThinOS 10, versions prior to 2605_10.2616, contain a Mi…6.7
- CVE-2026-81051Dell ThinOS 10, versions prior to 2605_10.2616, contain a Se…6.6
- CVE-2026-81052Dell ThinOS 10, versions prior to 2605_10.2616, contain a Do…6.8
- CVE-2026-8108The installation of Fuji Tellus adds a driver to the kernel …7.8
- CVE-2026-8109An exposed dangerous method on the Core Server of Ivanti End…6.5
- CVE-2026-81090The Gpx2Graphics WordPress plugin through 0.3 does not perfo…7.2
- CVE-2026-81091The proxy middleware in mcp-use's inspector forwards request…8.6
- CVE-2026-81092mcp-go accepted requests on its HTTP transports without chec…6.8
- CVE-2026-81093The get-html-skeleton tool fetched a URL the caller supplied…8.6
Are you affected by CVE-2026-8106?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
