THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8cj9-r88m-8945 (high) — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

[GHSA] GHSA-8cj9-r88m-8945 (high) — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

highgithub_advisoriesPublished 2026-09-03

GHSA-8cj9-r88m-8945 Severity: high CVE: CVE-2026-73292

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

### Summary

The password change form is vulnerable to CSRF, allowing an attacker to change a user password (even the administrator) by tricking a connected user to visit a malicious website. The vulnerability has been tested with version 2.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8cj9-r88m-8945