SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-73682

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Semaphore versions prior to 2.18.20 are vulnerable to an OS command injection flaw in the handling of the git_url parameter, allowing authenticated users with Manager or Owner roles to execute arbitrary shell commands on the server. This vulnerability poses a significant risk of remote code execution, potentially compromising the entire Semaphore server environment. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-73682
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
GitHub

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub