CVE-2026-91994: Semaphoreui Semaphore
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.
Affected products
- Semaphoreui Semaphore: up to and including 2.19.12
Published 2026-09-15. Last modified 2026-09-24.