Missing Authorization Affecting lemur package, versions [,1.9.3)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.08% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-LEMUR-19436355
  • published31 Aug 2026
  • disclosed18 Aug 2026
  • creditUnknown

Introduced: 18 Aug 2026

NewCVE-2026-71317  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade lemur to version 1.9.3 or higher.

Overview

lemur is a Certificate management and orchestration service

Affected versions of this package are vulnerable to Missing Authorization in the POST /api/1/authorities process when the ADMIN_ONLY_AUTHORITY_CREATION configuration is set to False. An attacker can gain unauthorized control over certificate authority creation by submitting requests that specify a parent authority for which they lack proper permissions, resulting in the ability to mint intermediate certificate authorities chained to internal roots and issue trusted certificates for arbitrary domains.

Note: This is only exploitable if the deployment has ADMIN_ONLY_AUTHORITY_CREATION=False and the attacker is an authenticated non-read-only user.

CVSS Base Scores

version 4.0
version 3.1