Beveiligingsadvies

CVE-2026-91994

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 11:35:49
Laatst bijgewerkt 2026-09-15 12:36:59
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.