CVE-2026-71307 | Netflix Lemur up to 1.9.2 sftp-destination plugin password/privateKeyPass information disclosure

SecurityVulns

A vulnerability classified as problematic was found in Netflix Lemur up to 1.9.2. This vulnerability affects unknown code of the component sftp-destination plugin. The manipulation of the argument password/privateKeyPass results in information disclosure.

This vulnerability is cataloged as CVE-2026-71307. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More