Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-91994

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Sep 15, 2026
Vendor unknown

Description

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.

References