CVE-2026-91994 UNKNOWN

CVE-2026-91994

Published: 2026-09-15

Description

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…