Summary
| Vulnerability Name | GitHub Enterprise Remote Code Execution (CVE-2026-3854) |
| Released on | April 29, 2026 |
| Affected Component | GitHub Enterprise |
| Affected Version | GitHub Enterprise Server ≤ 3.19.1 |
| Vulnerability Type | Code execution |
| Exploitation Condition | 1. User authentication: required. 2. Preconditions: default configurations. 3. Trigger mode: remote. |
| Impact | Exploitation difficulty: difficult. Only authorized attackers with push permissions can exploit this vulnerability. Severity: critical. This vulnerability may lead to remote code execution. |
| Official Solution | Available |
About the Vulnerability
Component Introduction
GitHub Enterprise is an enterprise-level software development and collaboration platform that supports self-hosted or cloud deployments. It provides enhanced security, identity management, and compliance features, and can help teams build reliable software efficiently.
Vulnerability Description
On April 29, 2026, Sangfor FarSight Labs received notification of the remote code execution vulnerability in GitHub Enterprise (CVE-2026-3854), classified as critical in threat level.
GitHub Enterprise Server is open-source software released by GitHub in the United States. It allows users to set up their GitHub instance as a virtual device, thereby providing a scalable and easy-to-manage platform.
A remote code execution vulnerability exists in GitHub Enterprise Server versions 3.14.24, 3.15.19, 3.16.15, 3.17.12, 3.18.6, and 3.19.3. This vulnerability stems from improper neutralization of push option values, which may lead to remote code execution.
Affected Versions
The following GitHub Enterprise versions are affected:
GitHub Enterprise Server ≤ 3.19.1
Solutions
Remediation Solutions
Official Solutions
The latest versions have been officially released to fix the vulnerability. Affected users are advised to update GitHub Enterprise Server to one of the following versions as needed:
- GitHub Enterprise Server 3.14.25 or later
- GitHub Enterprise Server 3.15.20 or later
- GitHub Enterprise Server 3.16.16 or later
- GitHub Enterprise Server 3.17.13 or later
- GitHub Enterprise Server 3.18.7 or later
- GitHub Enterprise Server 3.19.4 or later
- GitHub Enterprise Server 3.20.0 or later
Download links:
https://docs.github.com/en/[email protected]/admin/release-notes#3.14.25
https://docs.github.com/en/[email protected]/admin/release-notes#3.15.20
https://docs.github.com/en/[email protected]/admin/release-notes#3.16.16
https://docs.github.com/en/[email protected]/admin/release-notes#3.17.13
https://docs.github.com/en/[email protected]/admin/release-notes#3.18.7
https://docs.github.com/en/[email protected]/admin/release-notes#3.19.4
Temporary Solutions
- Disable unused functional modules to reduce attack entry points.
- Follow the principle of least privilege to strictly control the scope of permissions for sensitive operations.
- Do not expose services to the Internet unless necessary, to limit the access sources to trusted ranges.
- Regularly update the system and components to secure versions so that known vulnerabilities can be patched at the earliest opportunity.
Sangfor Solutions
Proactive Vulnerability Detection
The following Sangfor services can proactively detect CVE-2026-3854 vulnerabilities and quickly identify vulnerability risks in batches in business scenarios:
- Athena Managed Detection and Response (MDR): The corresponding detection solution will be released on May 30, 2026. The rule ID is SF-2026-01017.
- Athena Extended Detection and Response (XDR): The corresponding detection solution will be released on May 06, 2026. The rule ID is SF-2026-00906.
Vulnerability Monitoring
The following Sangfor services support CVE-2026-3854 vulnerability monitoring, and can quickly identify affected assets and the impact scope in business scenarios in real time through traffic collection:
- Athena Network Detection and Response (NDR): The corresponding monitoring solution will be released on May 11, 2026. The rule ID is 11220423.
- Athena MDR: The corresponding monitoring solution will be released on May 11, 2026. The rule ID is 11220423. In this case, make sure that Athena MDR is integrated with Athena NDR.
- Athena XDR: The corresponding monitoring solution will be released on May 11, 2026. The rule ID is 11220423.
Vulnerability Prevention
The following Sangfor services can effectively block CVE-2026-3854 exploits:
- Athena Next-Generation Firewall (NGFW): The corresponding prevention solution will be released on May 11, 2026. The rule ID is 11220423.
- Sangfor Web Application Firewall (WAF): The corresponding prevention solution will be released on May 11, 2026. The rule ID is 11220423.
- Athena MDR: The corresponding prevention solution will be released on May 11, 2026. The rule ID is 11220423. In this case, make sure that Athena MDR is integrated with Athena NGFW.
- Athena XDR: The corresponding prevention solution will be released on May 11, 2026. The rule ID is 11220423. In this case, make sure that Athena XDR is integrated with Athena NGFW.
Timeline
On April 29, 2026, Sangfor FarSight Labs received notification of the remote code execution vulnerability in GitHub Enterprise (CVE-2026-3854).
On April 29, 2026, Sangfor FarSight Labs released a vulnerability alert.
Reference
https://github.com/advisories/ghsa-64fw-jx9p-5j24
Learn More
Sangfor FarSight Labs researches the latest cyber threats and unknown zero-day vulnerabilities, alerting customers to potential dangers to their organizations, and providing real-time solutions with actionable intelligence. Sangfor FarSight Labs works with other security vendors and the security community at large to identify and verify global cyber threats, providing fast and easy protection for customers.