CVE-2026-4821: Proxy configuration command injection vulnerability found in GitHub Enterprise Server Management Console configuration API
Published Apr 21, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it was published in error.
Affected Software
8 affected components
GitHub GitHub Enterprise Server<3.21
GitHub Enterprise Server<3.14.26
GitHub Enterprise Server>=3.15.0<3.15.21
GitHub Enterprise Server>=3.16.0<3.16.17
GitHub Enterprise Server>=3.17.0<3.17.14
GitHub Enterprise Server>=3.18.0<3.18.8
GitHub Enterprise Server>=3.19.0<3.19.5
GitHub Enterprise Server=3.20.0
Event History
Apr 21, 2026
CVE Published
via MITRE·10:12 PM
Rejected
via MITRE·10:12 PM
Data Sourced
via NVD·11:16 PM
Description
Jun 10, 2026
Rejected
via MITRE·04:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-4821?
CVE-2026-4821 is classified as a high severity vulnerability due to its potential for exploitation via command injection.
2
How do I fix CVE-2026-4821?
To fix CVE-2026-4821, update your GitHub Enterprise Server to version 3.21 or later that includes the patch for this vulnerability.
3
What types of systems are affected by CVE-2026-4821?
CVE-2026-4821 affects GitHub Enterprise Server versions prior to 3.21.
4
Who can exploit CVE-2026-4821?
CVE-2026-4821 can be exploited by an authenticated Management Console administrator due to improper handling of input.
5
What actions can be taken to mitigate CVE-2026-4821?
Mitigation actions include restricting access to the Management Console and regularly updating GitHub Enterprise Server to the latest version.