CVE-2026-73292Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in version 2.18.21.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352CWE-620

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-12: 2Technical Details · 2026-08-12: 208-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-73292 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticate… https://www.cve.org/CVERecord?id=CVE-2026-73292 ----- Traducción: CVE-2026-73292 Sem… http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE-2026-73292, a cross‑site request flaw in Semaphore UI prior to version 2.18.21, without indicating exploitation, patch, or evidence of active attacks.

    0000032
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-73292 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticate… https://www.cve.org/CVERecord?id=CVE-2026-73292

    Post summary

    A new CVE (CVE‑2026‑73292) for Semaphore UI is disclosed, highlighting a cross‑site request vulnerability on the /api/users/{id}/password endpoint for versions before 2.18.21, with no PoC, exploit, or patch details provided.

    00000896
    57.9K followersView on X

Explore more