Lemur TLS Certificate Management Vulnerability Affecting Role Permissions
CVE-2026-55163
6.3MEDIUM
What is CVE-2026-55163?
A vulnerability in Lemur, a TLS certificate management tool, allows unauthorized updates to role permissions before version 1.9.2. The issue arises from the PUT method in the roles view, which incorrectly authorized updates through RoleMemberPermission. This flaw permits non-administrative users to change roles, such as adding or removing users and renaming roles, potentially leading to unauthorized access to sensitive certificates and authorities. The inconsistency in the handlers' permissions has been addressed in version 1.9.2, which now requires administrative rights for the PUT method, aligning it with the existing DELETE method.
Affected Version(s)
lemur < 1.9.2
