Description
Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Exposure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows GET and HEAD requests to bypass project resource permission checks, enabling users with guest or task_runner roles to retrieve entire project environments, including plaintext secrets, credentials, and passwords. This is an authorization bypass flaw classified under CWE‑862 that results in the exposure of sensitive configuration data.

Affected Systems

Semaphore UI version 2.19.12 and earlier releases are impacted. The flaw exists in the project environment API where the GetMustCanMiddleware does not enforce permission checks for GET and HEAD methods.

Risk and Exploitability

The CVSS score of 7.1 indicates medium‑to‑high severity. Attackers only need to authenticate as a guest or task_runner and then send simple HTTP GET or HEAD requests to the environment endpoint, a remote network attack path. The EPSS score of <1% suggests a very low expected exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, the ease of the attack and the value of the exposed secrets make the risk significant if the flaw remains unpatched.

Generated by OpenCVE AI on September 17, 2026 at 17:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Semaphore UI to version 2.19.13 or later to eliminate the permission bypass in the environment API.
  • If a newer release is unavailable, apply a vendor patch that restores permission checks for GET and HEAD requests.
  • In the absence of an immediate patch, restrict access to the environment endpoint by adding explicit role checks or by disabling GET and HEAD methods for unauthenticated or low‑privilege users.

Generated by OpenCVE AI on September 17, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Semaphoreui
Semaphoreui semaphore
Vendors & Products Semaphoreui
Semaphoreui semaphore

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.
Title Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Semaphoreui Semaphore
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:33.738Z

Reserved: 2026-09-15T11:11:13.312Z

Link: CVE-2026-91994

cve-icon Vulnrichment

Updated: 2026-09-15T12:36:51.431Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T12:17:54.793

Modified: 2026-09-24T20:28:01.780

Link: CVE-2026-91994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses