Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise (CVE-2026-55166)
Lemur versions prior to 1.9.2 contain a critical vulnerability that allows any SSO-authenticated user to compromise AWS IAM credentials and permanently access TLS private keys. This is due to a chain of three issues: automatic activation of new SSO users without approval, an SSRF vulnerability in the ACME authority creation endpoint that allows server-side requests to AWS EC2 metadata service, and an IDOR that grants the original certificate creator persistent access to private keys even after ownership transfer.
AI Analysis
Technical Summary
Lemur 1.9.0 and earlier versions have a combined vulnerability chain involving three independent flaws: (1) Lemur auto-provisions any new SSO identity as active without admin approval or restrictions, allowing any federated IdP user to become an active Lemur user; (2) the ACME authority creation endpoint accepts an attacker-controlled acme_url parameter and performs an unrestricted server-side HTTP fetch, enabling SSRF attacks to the AWS EC2 metadata service at 169.254.169.254, leaking AWS IAM credentials; (3) the certificate key-fetch endpoint grants unconditional access to the certificate's original creator regardless of ownership transfer, allowing persistent private key exfiltration. Together, these flaws enable a low-privilege SSO user to exfiltrate AWS STS credentials of the Lemur worker role and obtain permanent copies of TLS private keys issued by Lemur.
Potential Impact
An attacker with any valid SSO session in the Lemur environment can escalate privileges to compromise AWS IAM credentials associated with the Lemur worker role and permanently access TLS private keys issued by Lemur. This leads to a complete compromise of AWS resources accessible by the worker role and undermines the confidentiality and integrity of TLS certificates managed by Lemur. The vulnerability chain bypasses normal authorization controls and ownership transfer mechanisms, resulting in persistent unauthorized access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict SSO access to trusted users only and monitor for suspicious ACME authority creation requests. Consider disabling or restricting the ACME authority creation endpoint and reviewing certificate key access policies to limit exposure. Do not rely on ownership transfer to revoke creator access. Follow vendor advisories closely for updates and apply patches promptly once released.
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise (CVE-2026-55166)
Description
Lemur versions prior to 1.9.2 contain a critical vulnerability that allows any SSO-authenticated user to compromise AWS IAM credentials and permanently access TLS private keys. This is due to a chain of three issues: automatic activation of new SSO users without approval, an SSRF vulnerability in the ACME authority creation endpoint that allows server-side requests to AWS EC2 metadata service, and an IDOR that grants the original certificate creator persistent access to private keys even after ownership transfer.
CVSS v3.1
Score 9.9critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Lemur 1.9.0 and earlier versions have a combined vulnerability chain involving three independent flaws: (1) Lemur auto-provisions any new SSO identity as active without admin approval or restrictions, allowing any federated IdP user to become an active Lemur user; (2) the ACME authority creation endpoint accepts an attacker-controlled acme_url parameter and performs an unrestricted server-side HTTP fetch, enabling SSRF attacks to the AWS EC2 metadata service at 169.254.169.254, leaking AWS IAM credentials; (3) the certificate key-fetch endpoint grants unconditional access to the certificate's original creator regardless of ownership transfer, allowing persistent private key exfiltration. Together, these flaws enable a low-privilege SSO user to exfiltrate AWS STS credentials of the Lemur worker role and obtain permanent copies of TLS private keys issued by Lemur.
Potential Impact
An attacker with any valid SSO session in the Lemur environment can escalate privileges to compromise AWS IAM credentials associated with the Lemur worker role and permanently access TLS private keys issued by Lemur. This leads to a complete compromise of AWS resources accessible by the worker role and undermines the confidentiality and integrity of TLS certificates managed by Lemur. The vulnerability chain bypasses normal authorization controls and ownership transfer mechanisms, resulting in persistent unauthorized access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict SSO access to trusted users only and monitor for suspicious ACME authority creation requests. Consider disabling or restricting the ACME authority creation endpoint and reviewing certificate key access policies to limit exposure. Do not rely on ownership transfer to revoke creator access. Follow vendor advisories closely for updates and apply patches promptly once released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v2wp-frmc-5q3v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-55166"]
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a3ef7e527e9c79719032b38
Added to database: 06/26/2026, 22:06:29 UTC
Last enriched: 06/26/2026, 22:44:16 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 131
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.