CVE-2026-71307: CWE-862: Missing Authorization in Netflix lemur
Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw options and copied them into pluginOptions without redacting sensitive values. The sftp-destination plugin stored password and privateKeyPass values in plaintext, allowing even a read-only user to retrieve credentials for remote certificate-deployment hosts. The exposed credentials could permit direct access to SFTP systems and TLS material outside the Lemur security boundary. The fix requires administrator permission for destination reads and redacts options marked sensitive. This issue is fixed in version 1.9.3.
AI Analysis
Technical Summary
Netflix Lemur versions before 1.9.3 contain a missing authorization vulnerability (CWE-862) where GET /api/1/destinations and GET /api/1/destinations/ endpoints only required authentication but not administrator permissions. These endpoints returned raw options including sensitive data such as passwords and private key passphrases stored in plaintext by the sftp-destination plugin. This exposure allows users with read-only privileges to retrieve credentials that could be used to access remote certificate deployment hosts and TLS materials outside Lemur's security boundary. The vulnerability is resolved in version 1.9.3 by requiring administrator permissions for destination reads and redacting sensitive fields.
Potential Impact
An attacker with read-only access to Lemur prior to version 1.9.3 can retrieve plaintext credentials for SFTP destinations, potentially enabling unauthorized access to remote systems and TLS certificate materials. This compromises confidentiality but does not affect integrity or availability directly. The CVSS 3.1 base score is 7.7 (high), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and high confidentiality impact with no integrity or availability impact.
Mitigation Recommendations
Upgrade Lemur to version 1.9.3 or later, where this vulnerability is fixed by enforcing administrator permissions on destination read endpoints and redacting sensitive options. No other mitigation is indicated or required by the vendor advisory. Patch status is confirmed fixed in 1.9.3.
CVE-2026-71307: CWE-862: Missing Authorization in Netflix lemur
Description
Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw options and copied them into pluginOptions without redacting sensitive values. The sftp-destination plugin stored password and privateKeyPass values in plaintext, allowing even a read-only user to retrieve credentials for remote certificate-deployment hosts. The exposed credentials could permit direct access to SFTP systems and TLS material outside the Lemur security boundary. The fix requires administrator permission for destination reads and redacts options marked sensitive. This issue is fixed in version 1.9.3.
CVSS v3.1
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Netflix Lemur versions before 1.9.3 contain a missing authorization vulnerability (CWE-862) where GET /api/1/destinations and GET /api/1/destinations/ endpoints only required authentication but not administrator permissions. These endpoints returned raw options including sensitive data such as passwords and private key passphrases stored in plaintext by the sftp-destination plugin. This exposure allows users with read-only privileges to retrieve credentials that could be used to access remote certificate deployment hosts and TLS materials outside Lemur's security boundary. The vulnerability is resolved in version 1.9.3 by requiring administrator permissions for destination reads and redacting sensitive fields.
Potential Impact
An attacker with read-only access to Lemur prior to version 1.9.3 can retrieve plaintext credentials for SFTP destinations, potentially enabling unauthorized access to remote systems and TLS certificate materials. This compromises confidentiality but does not affect integrity or availability directly. The CVSS 3.1 base score is 7.7 (high), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and high confidentiality impact with no integrity or availability impact.
Mitigation Recommendations
Upgrade Lemur to version 1.9.3 or later, where this vulnerability is fixed by enforcing administrator permissions on destination read endpoints and redacting sensitive options. No other mitigation is indicated or required by the vendor advisory. Patch status is confirmed fixed in 1.9.3.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-05T18:14:42.063Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a84b07ac6e8be0332a47e50
Added to database: 08/18/2026, 19:20:26 UTC
Last enriched: 08/18/2026, 19:34:36 UTC
Last updated: 08/19/2026, 00:04:26 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.