Authorization Flaw in Lemur TLS Certificate Management
CVE-2026-70666
7.4HIGH
What is CVE-2026-70666?
The vulnerability in Lemur allows an unauthorized authority-role member to update the ACME URL without proper validation, enabling a potential attacker to redirect certificate management requests to a compromised ACME server. This server can respond with manipulated directory and order responses, which may expose sensitive internal services or cloud metadata to unauthorized access. The lack of host validation in Lemur's ClientV2 means that attackers can exploit this flaw without needing global administrator rights. A fix has been implemented in version 1.9.3, which ensures revalidation of updates and restricts the allowed hosts for the entire ACME process.
Affected Version(s)
lemur < 1.9.3
