Privilege Escalation Vulnerability in Lemur by Netflix
CVE-2026-44304

8.1HIGH

Key Information:

Vendor

Netflix

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-44304?

Lemur, a tool for managing TLS certificates, has a security issue in its LDAP authentication module that allows an authenticated user to manipulate LDAP search filters. This vulnerability arises from the use of unsanitized user input via Python string interpolation, which can lead to the injection of LDAP filter metacharacters through the username field. As a result, the attacker may escalate their privileges to become an administrator. This issue was addressed in version 1.9.0 of Lemur.

Affected Version(s)

lemur < 1.9.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.