Security Advisory

CVE-2026-91994

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 11:35:49
Last updated 2026-09-15 12:36:59
Assigner VulnCheck
CVSS score 7.1
State PUBLISHED

Description

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.