PatchSiren cyber security CVE debrief
CVE-2026-73293 semaphoreui CVE debrief
Semaphore UI, a web interface for managing DevOps tools, has a vulnerability prior to versions 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5. ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to create a custom manager role with permission bitmask 15, overriding built-in manager permissions and granting CanUpdateProject and CanManageProjectUsers owner capabilities.
- Vendor
- semaphoreui
- Product
- semaphore
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-09-09
Who should care
DevOps teams and administrators using Semaphore UI should assess exposure and verify their environment's version to determine if they are affected by this vulnerability. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls
Why it matters
Defenders should care about CVE-2026-73293 because it allows project managers in Semaphore UI to create custom roles with elevated permissions, potentially leading to privilege escalation and unauthorized project updates. DevOps teams and administrators should verify their environment's version and assess exposure to determine if they are affected.
- Potential elevation of project manager privileges
- Increased risk of unauthorized project updates
- Possible exploitation of custom role creation
Technical summary
The vulnerability allows project managers to create a custom manager role with permission bitmask 15, granting CanUpdateProject and CanManageProjectUsers owner capabilities, prior to Semaphore UI versions 2.18.19 and 2.19.5-beta5. This issue is fixed in versions 2.18.19 and 2.19.5-beta5. The Semaphore UI web interface for managing DevOps tools has a vulnerability that allows project managers to override built-in manager permissions. Defenders should prioritize verifying exposure in DevOps environments using Semaphore UI, especially where project managers have elevated permissions.
Defensive priority
Defenders should prioritize verifying exposure in DevOps environments using Semaphore UI, especially where project managers have elevated permissions.
Recommended defensive actions
- Verify Semaphore UI version and assess exposure in DevOps environments
- Restrict project manager permissions to prevent role escalation
- Monitor for unusual role creation or permission changes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or specific attack vectors. The Semaphore UI vulnerability allows project managers to create custom roles with elevated permissions, potentially leading to privilege escalation and unauthorized project updates. Defenders should verify their environment's version and assess exposure to determine if they are affected. The official CVE Program record and NIST NVD detail page can
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73293 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73293
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73293 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73293
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/semaphoreui/semaphore/commit/1c4bb65df114962134f8829d4a03667106a01a68
-
Source reference
Unverified legacy reference
URL: https://github.com/semaphoreui/semaphore/commit/bb2a4e1f08c8023e618f8dd6eaca73554f2c33bb
-
Source reference
Unverified legacy reference
URL: https://github.com/semaphoreui/semaphore/releases/tag/v2.18.19
-
Source reference
Unverified legacy reference
URL: https://github.com/semaphoreui/semaphore/releases/tag/v2.19.5-beta5
-
Source reference
Unverified legacy reference
URL: https://github.com/semaphoreui/semaphore/security/advisories/GHSA-cxvf-gvfq-36w2
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.