CVE-2026-73292

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in version 2.18.21.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 16:17

Updated : 2026-09-09 21:02


NVD link : CVE-2026-73292

Mitre link : CVE-2026-73292

CVE.ORG link : CVE-2026-73292


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-620

Unverified Password Change