FR
live
High CVSS 7.3

CVE-2026-71417

NVD analysis in progress

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without requiring permission on the underlying authority. PUT /api/1/certificates//revoke authorized the caller against only the selected Lemur row, so the creator of the duplicate bypassed CertificatePermission. The duplicate had no cert.endpoints, which also bypassed the safeguard that prevents revocation of deployed certificates. Issuer plugins then revoked the real CA-side certificate using certificate.body or external_id under the stored authority credentials. An attacker could therefore revoke arbitrary managed certificates and cause fleet-wide TLS denial of service. The fix rejects duplicate authority_id and serial identities, requires authority access on upload, and checks every matching row during revocation. This issue is fixed in version 1.9.3.

What this means

Exposure
Exploitable with local access to the machine, with an ordinary user account and with no action from the victim.
Impact
An attacker can alter some data and take the service offline. The impact spreads beyond the vulnerable component into other parts of the system.
Weakness
Changing an identifier in the request grants access to another user’s data.
Likelihood
Its EPSS score stays low: nothing points to imminent exploitation, which is no reason to leave it unpatched.

What to doFold into the next patch cycle.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
18 August 2026
CVSS
7.3 (v3.1) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
EPSS
0.08% probability of exploitation within 30 days · above 0% of all CVEs
Weakness
CWE-639
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss