What is CVE-2026-73682?
CVE-2026-73682 is an OS command injection vulnerability in the git_url handling of Semaphore versions prior to 2.18.20. It allows authenticated users with Manager or Owner roles on any project to achieve remote code execution (RCE) on the Semaphore server. Upgrading to version 2.18.20 or later is strongly recommended.
Azərbaycanca: CVE-2026-73682 Semaphore platformunun (2.18.20-dən əvvəlki versiyalar) git_url idarəetməsində OS command injection zəifliyidir. Manager və ya Owner rolu olan autentifikasiya olunmuş istifadəçilərə serverdə uzaqdan kod icrası (RCE) imkanı verir. Dərhal 2.18.20 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of the Semaphore platform are affected by CVE-2026-73682?
This vulnerability affects Semaphore versions prior to 2.18.20.
What privilege level is required to exploit CVE-2026-73682?
It requires an authenticated user with Manager or Owner roles on any project.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.