CVE-2026-71417 | Netflix Lemur up to 1.9.2 Certificate Upload upload authority_id/serial/external_id privileges management

SecurityVulns

A vulnerability has been found in Netflix Lemur up to 1.9.2 and classified as problematic. The affected element is an unknown function of the file /api/1/certificates/upload of the component Certificate Upload. Performing a manipulation of the argument authority_id/serial/external_id results in improper privilege management.

This vulnerability is reported as CVE-2026-71417. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More