Netflix Lemur: 14 Coordinated Vulnerabilities Expose TLS Management Risks
Netflix's Lemur tool faces a critical disclosure of 14 vulnerabilities, including flaws in permission handling and ACME URL validation, patched in versions 1.9.1 through 1.9.3.

Key findings
- 14 vulnerabilities disclosed in Netflix's Lemur TLS certificate management tool on August 18, 2026.
- Critical vulnerability CVE-2026-55166 allows targeting internal services via ACME URL manipulation.
- Multiple high-severity flaws involve improper permission checks and insecure handling of ACME and certificate revocation URLs.
- Most issues patched in versions 1.9.1, 1.9.2, and 1.9.3; urgent updates recommended.
- Vulnerabilities span permission bypass, input validation flaws, and sensitive data exposure.
On August 18, 2026, a batch of 14 vulnerabilities was disclosed in Netflix's Lemur, an open-source tool for managing TLS certificate creation. The vulnerabilities, disclosed within a two-hour window, range in severity from medium to critical, with the most severe flaw, CVE-2026-55166, carrying a CVSSv3 score of 9.9. These issues collectively highlight weaknesses in permission handling, input validation, and data exposure within various API endpoints and internal services of Lemur.
Several vulnerabilities stem from improper permission checks. CVE-2026-71417, a high-severity flaw, allowed non-read-only users to create duplicate certificate entries without proper authority permissions. Similarly, CVE-2026-71317, a medium-severity issue, permitted the creation of sub-CA authorities without requiring permissions on the parent authority when certain configurations were in place. CVE-2026-71308, another high-severity vulnerability, accepted certificate replacement identifiers without a permission check, potentially allowing unauthorized modifications. CVE-2026-55163, a medium-severity bug, allowed any existing member of a role to update role information, not just administrators.
Input validation and data handling were also implicated in multiple disclosures. CVE-2026-71307, a high-severity vulnerability, involved DestinationOutputSchema returning sensitive values in API responses due to a lack of redaction. CVE-2026-71303 and CVE-2026-70666, both high-severity, allowed users with authority roles to bypass ACME URL validation and direct ACME client setup to attacker-controlled servers, potentially leading to the compromise of internal services. CVE-2026-70667 and CVE-2026-55162, both medium-severity, described issues where certificate revocation URLs (CRL/OCSP) were not adequately validated, allowing redirection to malicious destinations.
A critical vulnerability, CVE-2026-55166, allowed authenticated users to influence an ACME authority's URL without server-side restrictions, enabling backend requests to sensitive internal services or cloud instance metadata. CVE-2026-55165, a medium-severity flaw, involved a JWT verifier that used an unverified token's algorithm, potentially allowing for bypass of security checks. CVE-2026-55164, also medium-severity, detailed how administrator-initiated password changes bypassed the User.hash_password listener, leading to insecure password storage. Finally, CVE-2026-48508, a high-severity vulnerability, arose from incorrect initialization of permission checks in certain configurations, potentially weakening role-based access control.
The majority of these vulnerabilities were patched in Lemur version 1.9.3, with CVE-2026-55166, CVE-2026-55165, CVE-2026-55164, and CVE-2026-55163 addressed in version 1.9.2, and CVE-2026-48508 in version 1.9.1. Users are strongly advised to update to the latest available version of Lemur to mitigate these security risks. The coordinated disclosure of these numerous vulnerabilities underscores the importance of regular security audits and timely patching for critical infrastructure management tools like Lemur.
Key Findings:
- 14 vulnerabilities disclosed in Netflix's Lemur TLS certificate management tool on August 18, 2026.
- Critical vulnerability CVE-2026-55166 allows targeting internal services via ACME URL manipulation.
- Multiple high-severity flaws involve improper permission checks and insecure handling of ACME and certificate revocation URLs.
- Most issues patched in versions 1.9.1, 1.9.2, and 1.9.3; urgent updates recommended.
- Vulnerabilities span permission bypass, input validation flaws, and sensitive data exposure.
CVE IDs: CVE-2026-71417 CVE-2026-71322 CVE-2026-71317 CVE-2026-71308 CVE-2026-71307 CVE-2026-71303 CVE-2026-70666 CVE-2026-70667 CVE-2026-55166 CVE-2026-55165 CVE-2026-55164 CVE-2026-55163 CVE-2026-55162 CVE-2026-48508
Image Prompt: A stylized, abstract representation of a digital certificate with a padlock icon. The certificate is partially fragmented, with glowing lines of code seeping out from the cracks, symbolizing the vulnerabilities. The background is a dark, abstract network grid.