High severity8.8NVD Advisory· Published Aug 12, 2026· Updated Sep 9, 2026
CVE-2026-73293
CVE-2026-73293
Description
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a custom manager role with permission bitmask 15, overriding the built-in manager permissions and granting CanUpdateProject and CanManageProjectUsers owner capabilities. This issue is fixed in versions 2.18.19 and 2.19.5-beta5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/semaphoreui/semaphoreGo | < 0.0.0-20260705182501-bb2a4e1f08c8 | 0.0.0-20260705182501-bb2a4e1f08c8 |
Affected products
1- Range: 2.18.19, 2.19.5-beta5
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-cxvf-gvfq-36w2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-73293ghsaADVISORY
- github.com/semaphoreui/semaphore/commit/1c4bb65df114962134f8829d4a03667106a01a68nvdWEB
- github.com/semaphoreui/semaphore/commit/bb2a4e1f08c8023e618f8dd6eaca73554f2c33bbnvdWEB
- github.com/semaphoreui/semaphore/releases/tag/v2.18.19nvdWEB
- github.com/semaphoreui/semaphore/releases/tag/v2.19.5-beta5nvdWEB
- github.com/semaphoreui/semaphore/security/advisories/GHSA-cxvf-gvfq-36w2nvdWEB
News mentions
0No linked articles in our index yet.