PT-2026-77279 · Lemur · Lemur

CVE-2026-70666

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Lemur versions prior to 1.9.3
Description A member with an authority role can update the acme url via the 'PUT /api/1/authorities/' endpoint without revalidation. This allows the setup acme client no retry function to be directed to an attacker-controlled ACME server. Because the Lemur ClientV2 does not verify that the host of URLs in the ACME directory and order responses (such as newNonce, newOrder, authorizations, and finalize) matches the configured directory host, JWS-signed requests can be sent to internal services or cloud metadata endpoints. This issue requires an ACME authority and a user authorized for that authority, but does not require global administrator privileges.
Recommendations Update to version 1.9.3.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70666
GHSA-XPMJ-WJCP-6PWW
PYSEC-2026-3680

Affected Products

Lemur