Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-73294: Semaphore UI: Malicious Git Commands Can Be Run

CVE-2026-73294 · published 20 days ago
Summary

Semaphore UI's web interface for managing DevOps tools has a security issue that allows a malicious user to run arbitrary system commands on the server. This could potentially allow an attacker to access or modify sensitive data. To fix this issue, update Semaphore UI to version 2.18.17 or 2.19.5-beta2 or later.

What to do
  • Update semaphoreui semaphore to version 2.18.20 or later.
Affected software
VendorProductAffected versions
semaphoreui semaphore < 2.18.17
< 2.18.20
Original advisory text
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub
Severity
9.4 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published14 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Sources
CVE-2026-73294 · MITRE
Monitor software like this
Free during beta