Semaphore
Semaphoreui · 5 CVEs
CVE-2026-91994
HIGH
Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests
Sep 15, 2026
CVE-2026-73682
HIGH
Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling
Aug 14, 2026
CVE-2026-73294
CRITICAL
Semaphore U: OS Command Injection
Aug 12, 2026
CVE-2026-73293
HIGH
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
Aug 12, 2026
CVE-2026-73292
HIGH
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
Aug 12, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-91994 | Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests | HIGH | 0.41% | Sep 15, 2026 |
| CVE-2026-73682 | Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling | HIGH | 1.56% | Aug 14, 2026 |
| CVE-2026-73294 | Semaphore U: OS Command Injection | CRITICAL | 0.65% | Aug 12, 2026 |
| CVE-2026-73293 | Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision | HIGH | 0.57% | Aug 12, 2026 |
| CVE-2026-73292 | Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation | HIGH | 0.23% | Aug 12, 2026 |
Showing 1 to 5 of 5 CVEs