Privilege Escalation Vulnerability in Lemur by Netflix
CVE-2026-44304
8.1HIGH
What is CVE-2026-44304?
Lemur, a tool for managing TLS certificates, has a security issue in its LDAP authentication module that allows an authenticated user to manipulate LDAP search filters. This vulnerability arises from the use of unsanitized user input via Python string interpolation, which can lead to the injection of LDAP filter metacharacters through the username field. As a result, the attacker may escalate their privileges to become an administrator. This issue was addressed in version 1.9.0 of Lemur.
Affected Version(s)
lemur < 1.9.0
