CVE-2026-91994

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 12:17

Updated : 2026-09-15 13:16


NVD link : CVE-2026-91994

Mitre link : CVE-2026-91994

CVE.ORG link : CVE-2026-91994


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization