CVE-2026-48508 | Netflix Lemur up to 1.9.0 StrictRolePermission/AuthorityCreatorPermission permissions.py flask_principal.Permission.__init__ privileges management
A vulnerability was found in Netflix Lemur up to 1.9.0. It has been declared as critical. This affects the function flask_principal.Permission.__init__ of the file lemur/auth/permissions.py of the component StrictRolePermission/AuthorityCreatorPermission. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-48508. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More