PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73293 semaphoreui CVE debrief

Semaphore UI, a web interface for managing DevOps tools, has a vulnerability prior to versions 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5. ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to create a custom manager role with permission bitmask 15, overriding built-in manager permissions and granting CanUpdateProject and CanManageProjectUsers owner capabilities.

Vendor
semaphoreui
Product
semaphore
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-09
Advisory published
2026-08-12
Advisory updated
2026-09-09

Who should care

DevOps teams and administrators using Semaphore UI should assess exposure and verify their environment's version to determine if they are affected by this vulnerability. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls

Why it matters

Defenders should care about CVE-2026-73293 because it allows project managers in Semaphore UI to create custom roles with elevated permissions, potentially leading to privilege escalation and unauthorized project updates. DevOps teams and administrators should verify their environment's version and assess exposure to determine if they are affected.

  • Potential elevation of project manager privileges
  • Increased risk of unauthorized project updates
  • Possible exploitation of custom role creation

Technical summary

The vulnerability allows project managers to create a custom manager role with permission bitmask 15, granting CanUpdateProject and CanManageProjectUsers owner capabilities, prior to Semaphore UI versions 2.18.19 and 2.19.5-beta5. This issue is fixed in versions 2.18.19 and 2.19.5-beta5. The Semaphore UI web interface for managing DevOps tools has a vulnerability that allows project managers to override built-in manager permissions. Defenders should prioritize verifying exposure in DevOps environments using Semaphore UI, especially where project managers have elevated permissions.

Defensive priority

Defenders should prioritize verifying exposure in DevOps environments using Semaphore UI, especially where project managers have elevated permissions.

Recommended defensive actions

  • Verify Semaphore UI version and assess exposure in DevOps environments
  • Restrict project manager permissions to prevent role escalation
  • Monitor for unusual role creation or permission changes
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. However, there is no information on known exploitation or specific attack vectors. The Semaphore UI vulnerability allows project managers to create custom roles with elevated permissions, potentially leading to privilege escalation and unauthorized project updates. Defenders should verify their environment's version and assess exposure to determine if they are affected. The official CVE Program record and NIST NVD detail page can

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73293 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73293

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73293 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73293

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.