8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Description
Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group membership queries and escalate their privileges to administrator. This vulnerability is fixed in 1.9.0.
Basic Information
ID
CVE-2026-44304
Source
GitHub_M
Published
May 12, 2026 at 21:27
Affected Product
Vendor
Netflix
Product
lemur
Version
< 1.9.0
Affected Versions
Netflix lemur < 1.9.0