CVE-2026-73292 is a cross-site request forgery vulnerability in Semaphore UI before version 2.18.21. The password-change API accepts requests authenticated by a Semaphore session cookie without CSRF validation or confirmation of the current password. A malicious site can cause a victim's browser to submit a password-change request while the victim is authenticated, including for an administrative or other user account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept exploit for CVE-2026-73292 affecting Semaphore UI versions below 2.18.21. It contains one executable Python script (poc_server.py), a README describing the vulnerability and usage, and a minimal .gitignore. The exploit is not part of a known offensive framework. The core capability is browser-based CSRF against Semaphore UI's password change API. The Python script starts a local HTTP server and serves an HTML page containing an auto-submitting form. When an authenticated victim visits the attacker-controlled page, their browser submits a POST request to the target Semaphore endpoint /api/users/{user_id}/password using the victim's existing session cookie. The request sets a new attacker-chosen password and can lead to account takeover. Repository structure and behavior: - README.md: documents the vulnerability, affected endpoint, example request body, usage syntax, and reproduction steps. - poc_server.py: implements the exploit server. It parses CLI arguments for target URI, target user ID, new password, and listening port; generates the malicious HTML; logs inbound GET requests; and serves the page indefinitely via Python's built-in HTTPServer. - .gitignore: ignores a local semaphore/ directory. Notable implementation details: - forge_malicious_page() builds the malicious HTML form targeting {target}/api/users/{user_id}/password. - The form uses enctype="text/plain" and a crafted hidden input name to approximate a JSON body accepted by the vulnerable endpoint. - JavaScript immediately submits the form on page load, requiring only that the victim browse to the attacker page. Overall, this is a valid operational PoC exploit for authenticated cross-site password reset/account takeover, not merely a detector.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity cross-site request vulnerability in Semaphore UI's password-change API. An unauthenticated attacker can induce an authenticated user to change an administrator or other user's password because the endpoint lacks CSRF protection and current-password confirmation.
A cross-site request forgery vulnerability in Semaphore UI's password-change endpoint. It lacks a CSRF token and current-password confirmation, while relying on a session cookie without SameSite enforcement, enabling an attacker to cause an authenticated user—including an administrator—to have their password changed.
A vulnerability in Semaphore UI's /api/users/{id}/password endpoint that allows cross-site request abuse due to missing CSRF protection and no current-password confirmation, enabling password changes for an administrator or another user after user interaction.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.