PT-2026-77279 · Lemur · Lemur
CVE-2026-70666
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Lemur versions prior to 1.9.3
Description
A member with an authority role can update the
acme url via the 'PUT /api/1/authorities/' endpoint without revalidation. This allows the setup acme client no retry function to be directed to an attacker-controlled ACME server. Because the Lemur ClientV2 does not verify that the host of URLs in the ACME directory and order responses (such as newNonce, newOrder, authorizations, and finalize) matches the configured directory host, JWS-signed requests can be sent to internal services or cloud metadata endpoints. This issue requires an ACME authority and a user authorized for that authority, but does not require global administrator privileges.Recommendations
Update to version 1.9.3.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lemur