TLS Certificate Management Vulnerability in Lemur by Netflix
CVE-2026-71308
8.1HIGH
What is CVE-2026-71308?
A vulnerability in Lemur's TLS certificate management, affecting versions 0.5.0 to 1.9.3, allows authenticated non-read-only users to exploit the system by manipulating certificate management requests. Attackers can replace certificates they do not own, disrupt TLS lifecycle management, and potentially deploy unauthorized certificates across endpoints. The absence of proper permission checks opens avenues for certificate substitution, leading to vulnerabilities that can affect the entire TLS infrastructure. This issue has been resolved in version 1.9.3 with enhanced authorization for management operations.
Affected Version(s)
lemur >= 0.5.0, < 1.9.3
