PT-2026-77284 · Lemur · Lemur

CVE-2026-71317

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lemur versions prior to 1.9.3
Description An issue exists in the TLS certificate creation process where the endpoint "/api/1/authorities" does not properly verify permissions when the type parameter is set to subca and ADMIN ONLY AUTHORITY CREATION is false. The AssociatedAuthoritySchema resolves the parent authority provided by the caller and passes it to the cryptography-issuer, which uses the authority certificate.private key of the parent to sign a new intermediate certificate. This allows any authenticated non-read-only user to chain a sub-CA to an internal root without having the required role, enabling the issuance of trusted certificates and the use of the private key outside the system to bypass issuance controls.
Recommendations Update to version 1.9.3.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71317
GHSA-G7P5-89MH-248H
PYSEC-2026-3677

Affected Products

Lemur