๐Ÿ” CVE Alert

CVE-2026-73292

HIGH 8.3

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in version 2.18.21.

CWE CWE-352 CWE-620
Vendor semaphoreui
Product semaphore
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for semaphoreui semaphore

Be the first to know when new high vulnerabilities affecting semaphoreui semaphore are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

semaphoreui / semaphore
< 2.18.21

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/semaphoreui/semaphore/security/advisories/GHSA-8cj9-r88m-8945 github.com: https://github.com/semaphoreui/semaphore/commit/2d6e2e3eb10e8bf688e2ab59609b909a012fad4c github.com: https://github.com/semaphoreui/semaphore/commit/c59c3dc9035badcbf0609c7d35679c06e590a956 github.com: https://github.com/semaphoreui/semaphore/releases/tag/v2.18.21