CVE-2026-55164 | Netflix Lemur up to 1.9.1 Password Hashing lemur/users/models.py lemur.users.service.update missing encryption
A vulnerability was found in Netflix Lemur up to 1.9.1. It has been rated as problematic. This issue affects the function lemur.users.service.update of the file lemur/users/models.py of the component Password Hashing. Performing a manipulation of the argument Password results in missing encryption of sensitive data.
This vulnerability was named CVE-2026-55164. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More