CVE-2026-73292High· 8.3▾ MidnightPoC availableSemaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-pa…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 45.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
8.3 → 7.6
7.6 → 8.3
8.3 → 7.6
7.6 → 8.3
8.3 → 7.6
7.6 → 8.3
8.3 → 7.6
7.6 → 8.3
8.3 → 7.6
7.6 → 8.3
8.3 → 7.6
7.6 → 8.3
1 GitHub repo (last check)
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in version 2.18.21.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/semaphoreui/semaphore < 0.0.0-20260707190631-c59c3dc9035bPatched in:
github.com/semaphoreui/semaphore 0.0.0-20260707190631-c59c3dc9035bField changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73294Critical· 9.9Semaphore UI is a web interface for managing DevOps tools
CVE-2026-73293High· 8.8Semaphore UI is a web interface for managing DevOps tools
CVE-2019-13529High· 8.8An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior
CVE-2026-91994Medium· 6.5Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware
CVE-2017-20120Medium· 4.3A vulnerability classified as problematic was found in TrueConf Server 4.3.7
CVE-2024-0830Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0