CVE-2026-71308 | Netflix Lemur up to 1.9.2 Certificate Permission Check replaces[] improper authorization
A vulnerability described as problematic has been identified in Netflix Lemur up to 1.9.2. Affected by this issue is some unknown functionality of the component Certificate Permission Check. Executing a manipulation of the argument replaces[] can lead to improper authorization.
This vulnerability is tracked as CVE-2026-71308. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More