Skip to main content
EPSS 0.3%top 80%

Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise (CVE-2026-55166)

0
Critical
Published: 08/18/2026 (08/18/2026, 18:51:41 UTC)
Source: GCVE Database
Product: lemur

Description

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud instance metadata or internal services from Lemur network context, potentially obtaining credentials available to the host. The advisory also identifies creator-equality authorization behavior that could preserve access to certificate key material after ownership or role changes, with insufficient export_private_key audit context to distinguish that access path. Together, the acme_url server-side request forgery and authorization weakness could expose cloud credentials and long-lived PKI private-key access. The fix adds ACME_DIRECTORY_HOST_ALLOWLIST validation and enriches key-export audit events with creator and current-owner context. This issue is fixed in version 1.9.2.

CVSS v3.1

Score 9.9critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Affected software

PyPIghsa
lemur
Affected versions
<1.9.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 11:14:25 UTC

Technical Analysis

Lemur, a TLS certificate management tool, had a critical vulnerability (CVE-2026-55166) in versions before 1.9.2. Authenticated users could exploit an SSRF flaw by influencing the ACME authority URL (acme_url) without effective server-side destination restrictions, causing the backend to make requests to internal or cloud metadata services. This could lead to exposure of cloud credentials accessible to the host. Additionally, an authorization weakness involving creator-equality allowed users to retain access to certificate private keys after ownership or role changes, with inadequate audit context to distinguish this access path. The combined SSRF and authorization issues could result in compromise of AWS IAM credentials and long-lived PKI private keys. The fix in version 1.9.2 introduces ACME_DIRECTORY_HOST_ALLOWLIST validation and enriches key export audit logs with creator and current owner information.

Potential Impact

Successful exploitation could allow an authenticated attacker to perform server-side request forgery to access internal services or cloud instance metadata, potentially obtaining sensitive cloud credentials. The authorization flaw could permit unauthorized access to private certificate keys even after role or ownership changes, risking long-term compromise of PKI material. This could lead to full compromise of AWS IAM credentials and private keys managed by Lemur, severely impacting confidentiality and integrity of cloud and certificate infrastructure.

Mitigation Recommendations

A patch is available and the issue is fixed in Lemur version 1.9.2. Users should upgrade to version 1.9.2 or later to remediate this vulnerability. The fix includes validation of ACME directory hosts via an allowlist and improved audit logging for private key exports. No additional mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-v2wp-frmc-5q3v
Osv Schema Version
1.4.0
Aliases
["CVE-2026-55166"]
Ecosystems
["PyPI"]
Database Specific Severity
CRITICAL
Cvss Version
3.1

Threat ID: 6a3ef7e527e9c79719032b38

Added to database: 06/26/2026, 22:06:29 UTC

Last enriched: 08/19/2026, 11:14:25 UTC

Last updated: 09/14/2026, 22:01:35 UTC

Views: 227

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses