A vulnerability has been found in SemaphoreUI Semaphore up to 2.18.18/2.19.5-beta4 and classified as problematic. Affected is the function ProjectMiddleware/GetProjectOrGlobalRoleBySlug of the file /api/project/{id}/roles of the component Role Management. Performing a manipulation results in improper privilege management.

This vulnerability is identified as CVE-2026-73293. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.