CVE-2026-73292: Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in version 2.18.21.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Semaphore UIto a version that resolves this vulnerability.Fixed in 2.18.21
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73292?
The severity of CVE-2026-73292 is high with a score of 8.3.
How do I fix CVE-2026-73292?
To fix CVE-2026-73292, upgrade Semaphore UI to version 2.18.21 or later.
What kind of vulnerability is CVE-2026-73292?
CVE-2026-73292 is a Cross-Site Request Forgery (CSRF) vulnerability.
What impact does CVE-2026-73292 have on users?
CVE-2026-73292 allows an unauthenticated attacker to change passwords using the authenticated user's session.
Which software is affected by CVE-2026-73292?
CVE-2026-73292 affects Semaphore UI prior to version 2.18.21.