PT-2026-77283 · Lemur · Lemur

CVE-2026-71308

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lemur versions 0.5.0 through 1.9.2
Description An authenticated non-read-only user can target certificates they do not own or have a role for by using the replaces[] or replacements identifiers during certificate creation, upload, or edit requests. The AssociatedCertificateSchema resolves these identifiers using the fetch objects() function without performing a CertificatePermission check. Assigning these objects to Certificate.replaces triggers an append listener that marks the victim certificate as replaced and disables its notifications. Consequently, the victim certificate is excluded from get all pending reissue(), allowing certificate rotate() to deploy an attacker-controlled certificate to endpoints serving the victim. This can lead to unauthorized certificate substitution or fleet-wide TLS disruption by suppressing lifecycle automation.
Recommendations Update Lemur to version 1.9.3.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71308
GHSA-CFH6-PV5C-38JV
PYSEC-2026-3675

Affected Products

Lemur