Vendor
high
advisory
Semaphore UI Privilege Escalation via Custom Role Slug Collision
1 TTP 1 CVESemaphore UI is vulnerable to a privilege escalation where a project manager can create a colliding custom role slug to assign themselves owner-level permissions, bypassing access controls.
Semaphore
privilege-escalation
web-application
cve
1t
1c
high
advisory
CVE-2026-73682 Remote Code Execution in Semaphore
1 TTP 1 CVESemaphore versions prior to 2.18.20 contain an argument injection vulnerability allowing authenticated users with Manager or Owner roles to achieve remote code execution via malicious git_url parameters.
Semaphore
1t
1c