๐Ÿ” CVE Alert

CVE-2026-73293

HIGH 8.8

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a custom manager role with permission bitmask 15, overriding the built-in manager permissions and granting CanUpdateProject and CanManageProjectUsers owner capabilities. This issue is fixed in versions 2.18.19 and 2.19.5-beta5.

CWE CWE-269
Vendor semaphoreui
Product semaphore
Published Aug 12, 2026
Last Updated Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for semaphoreui semaphore

Be the first to know when new high vulnerabilities affecting semaphoreui semaphore are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

semaphoreui / semaphore
< 2.18.19 >= 2.19.0-alpha3, < 2.19.5-beta5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/semaphoreui/semaphore/security/advisories/GHSA-cxvf-gvfq-36w2 github.com: https://github.com/semaphoreui/semaphore/commit/1c4bb65df114962134f8829d4a03667106a01a68 github.com: https://github.com/semaphoreui/semaphore/commit/bb2a4e1f08c8023e618f8dd6eaca73554f2c33bb github.com: https://github.com/semaphoreui/semaphore/releases/tag/v2.18.19 github.com: https://github.com/semaphoreui/semaphore/releases/tag/v2.19.5-beta5