{"id":"CVE-2026-73292","title":"Semaphore UI is a web interface for managing DevOps tools","summary":"Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-pa…","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","cwe":["CWE-352","CWE-620"],"vendor":"semaphoreui","product":"github.com/semaphoreui/semaphore","affected":["github.com/semaphoreui/semaphore < 0.0.0-20260707190631-c59c3dc9035b"],"patched":["github.com/semaphoreui/semaphore 0.0.0-20260707190631-c59c3dc9035b"],"published":"2026-08-12","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:02:22.660","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73292","references":[{"url":"https://github.com/semaphoreui/semaphore/commit/2d6e2e3eb10e8bf688e2ab59609b909a012fad4c","label":"security-advisories@github.com"},{"url":"https://github.com/semaphoreui/semaphore/commit/c59c3dc9035badcbf0609c7d35679c06e590a956","label":"security-advisories@github.com"},{"url":"https://github.com/semaphoreui/semaphore/releases/tag/v2.18.21","label":"security-advisories@github.com"},{"url":"https://github.com/semaphoreui/semaphore/security/advisories/GHSA-8cj9-r88m-8945","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73292"},{"url":"https://github.com/advisories/GHSA-8cj9-r88m-8945"}],"tags":["nvd","exploit-available","ghsa","go"],"epss":0.00233,"epssPercentile":0.14486,"exploits":{"github":1,"githubRepos":["https://github.com/CamilleGR/CVE-2026-73292"],"checkedAt":"2026-09-21T15:30:28.563Z"},"exploitAvailable":true,"aliases":["GHSA-8cj9-r88m-8945"],"ecosystem":"go","scores":{"nvd":8.3,"ghsa":7.6},"ingestedAt":"2026-09-03T20:08:06.763Z","slug":"CVE-2026-73292","body":"## Overview\n\nSemaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in version 2.18.21.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-73292)\n\nAffected packages:\n\n- `github.com/semaphoreui/semaphore < 0.0.0-20260707190631-c59c3dc9035b`\n\nPatched in:\n\n- `github.com/semaphoreui/semaphore 0.0.0-20260707190631-c59c3dc9035b`\n\nSource: https://github.com/advisories/GHSA-8cj9-r88m-8945","depth":"midnight","depthScore":58,"depthScoreParts":{"impact":45.7,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":201896,"id":"CVE-2026-73292","ts":1789399978374,"field":"cvss","old":"7.6","new":"8.3"},{"seq":200626,"id":"CVE-2026-73292","ts":1789397538682,"field":"cvss","old":"8.3","new":"7.6"},{"seq":199340,"id":"CVE-2026-73292","ts":1789395457588,"field":"cvss","old":"7.6","new":"8.3"},{"seq":198585,"id":"CVE-2026-73292","ts":1789392137191,"field":"cvss","old":"8.3","new":"7.6"},{"seq":198540,"id":"CVE-2026-73292","ts":1789392064884,"field":"cvss","old":"7.6","new":"8.3"},{"seq":196331,"id":"CVE-2026-73292","ts":1789383703896,"field":"cvss","old":"8.3","new":"7.6"},{"seq":195260,"id":"CVE-2026-73292","ts":1789380543113,"field":"cvss","old":"7.6","new":"8.3"},{"seq":194047,"id":"CVE-2026-73292","ts":1789378650229,"field":"cvss","old":"8.3","new":"7.6"},{"seq":192834,"id":"CVE-2026-73292","ts":1789376480486,"field":"cvss","old":"7.6","new":"8.3"},{"seq":191621,"id":"CVE-2026-73292","ts":1789373557016,"field":"cvss","old":"8.3","new":"7.6"},{"seq":190406,"id":"CVE-2026-73292","ts":1789369420794,"field":"cvss","old":"7.6","new":"8.3"},{"seq":189193,"id":"CVE-2026-73292","ts":1789368348611,"field":"cvss","old":"8.3","new":"7.6"},{"seq":187976,"id":"CVE-2026-73292","ts":1789365203611,"field":"cvss","old":"7.6","new":"8.3"},{"seq":186763,"id":"CVE-2026-73292","ts":1789363413185,"field":"cvss","old":"8.3","new":"7.6"},{"seq":185549,"id":"CVE-2026-73292","ts":1789361184906,"field":"cvss","old":"7.6","new":"8.3"},{"seq":184336,"id":"CVE-2026-73292","ts":1789358276313,"field":"cvss","old":"8.3","new":"7.6"},{"seq":182587,"id":"CVE-2026-73292","ts":1789354278100,"field":"cvss","old":"7.6","new":"8.3"},{"seq":181380,"id":"CVE-2026-73292","ts":1789353249334,"field":"cvss","old":"8.3","new":"7.6"},{"seq":180173,"id":"CVE-2026-73292","ts":1789350231292,"field":"cvss","old":"7.6","new":"8.3"},{"seq":178966,"id":"CVE-2026-73292","ts":1789348225566,"field":"cvss","old":"8.3","new":"7.6"},{"seq":177759,"id":"CVE-2026-73292","ts":1789346345809,"field":"cvss","old":"7.6","new":"8.3"},{"seq":176552,"id":"CVE-2026-73292","ts":1789343131843,"field":"cvss","old":"8.3","new":"7.6"},{"seq":174669,"id":"CVE-2026-73292","ts":1789334842853,"field":"cvss","old":"7.6","new":"8.3"},{"seq":173464,"id":"CVE-2026-73292","ts":1789333618985,"field":"cvss","old":"8.3","new":"7.6"},{"seq":172278,"id":"CVE-2026-73292","ts":1789331069650,"field":"cvss","old":"7.6","new":"8.3"},{"seq":171092,"id":"CVE-2026-73292","ts":1789328715680,"field":"cvss","old":"8.3","new":"7.6"},{"seq":169887,"id":"CVE-2026-73292","ts":1789327131878,"field":"cvss","old":"7.6","new":"8.3"},{"seq":168682,"id":"CVE-2026-73292","ts":1789323771076,"field":"cvss","old":"8.3","new":"7.6"},{"seq":167477,"id":"CVE-2026-73292","ts":1789319658181,"field":"cvss","old":"7.6","new":"8.3"},{"seq":166272,"id":"CVE-2026-73292","ts":1789318697857,"field":"cvss","old":"8.3","new":"7.6"},{"seq":165067,"id":"CVE-2026-73292","ts":1789315763593,"field":"cvss","old":"7.6","new":"8.3"},{"seq":163862,"id":"CVE-2026-73292","ts":1789313570776,"field":"cvss","old":"8.3","new":"7.6"},{"seq":162657,"id":"CVE-2026-73292","ts":1789311876079,"field":"cvss","old":"7.6","new":"8.3"},{"seq":161452,"id":"CVE-2026-73292","ts":1789308663016,"field":"cvss","old":"8.3","new":"7.6"},{"seq":159565,"id":"CVE-2026-73292","ts":1789300447222,"field":"cvss","old":"7.6","new":"8.3"},{"seq":156554,"id":"CVE-2026-73292","ts":1789294701574,"field":"cvss","old":"8.3","new":"7.6"},{"seq":155349,"id":"CVE-2026-73292","ts":1789292871515,"field":"cvss","old":"7.6","new":"8.3"},{"seq":154144,"id":"CVE-2026-73292","ts":1789289724789,"field":"cvss","old":"8.3","new":"7.6"},{"seq":152794,"id":"CVE-2026-73292","ts":1789281632174,"field":"cvss","old":"7.6","new":"8.3"},{"seq":152434,"id":"CVE-2026-73292","ts":1789281207928,"field":"cvss","old":"8.3","new":"7.6"},{"seq":151395,"id":"CVE-2026-73292","ts":1789277602944,"field":"cvss","old":"7.6","new":"8.3"},{"seq":150356,"id":"CVE-2026-73292","ts":1789276195422,"field":"cvss","old":"8.3","new":"7.6"},{"seq":149323,"id":"CVE-2026-73292","ts":1789273797504,"field":"cvss","old":"7.6","new":"8.3"},{"seq":148290,"id":"CVE-2026-73292","ts":1789271273496,"field":"cvss","old":"8.3","new":"7.6"},{"seq":146322,"id":"CVE-2026-73292","ts":1789269346452,"field":"cvss","old":"7.6","new":"8.3"},{"seq":145127,"id":"CVE-2026-73292","ts":1789266296641,"field":"cvss","old":"8.3","new":"7.6"},{"seq":144031,"id":"CVE-2026-73292","ts":1789262579498,"field":"cvss","old":"7.6","new":"8.3"},{"seq":142935,"id":"CVE-2026-73292","ts":1789261468700,"field":"cvss","old":"8.3","new":"7.6"},{"seq":141766,"id":"CVE-2026-73292","ts":1789258805308,"field":"cvss","old":"7.6","new":"8.3"},{"seq":140607,"id":"CVE-2026-73292","ts":1789256682234,"field":"cvss","old":"8.3","new":"7.6"}]}