CVE-2026-71417 | Netflix Lemur up to 1.9.2 Certificate Upload upload authority_id/serial/external_id privileges management
A vulnerability has been found in Netflix Lemur up to 1.9.2 and classified as problematic. The affected element is an unknown function of the file /api/1/certificates/upload of the component Certificate Upload. Performing a manipulation of the argument authority_id/serial/external_id results in improper privilege management.
This vulnerability is reported as CVE-2026-71417. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More