CVE 8.1 HIGH

Lemur: LDAP Filter Injection enables post-authentication privilege escalation_CVE-2026-44304

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group membership queries and escalate their privileges to administrator. This vulnerability is fixed in 1.9.0.

Basic Information

ID CVE-2026-44304
Source GitHub_M
Published May 12, 2026 at 21:27

Affected Product

Vendor Netflix
Product lemur
Version < 1.9.0
Affected Versions Netflix lemur < 1.9.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.