What is CVE-2026-55166?
A vulnerability (CVE-2026-55166) was found in Lemur, a TLS certificate management tool. Before version 1.9.2, authenticated users could manipulate the ACME "acme_url" without proper server-side restrictions, allowing backend requests to internal services like cloud instance metadata. Affected users must upgrade to version 1.9.2 or later immediately.
Azərbaycanca: Lemur TLS sertifikat idarəetmə sistemində CVE-2026-55166 zəifliyi aşkar edilib. 1.9.2 versiyasından əvvəl, autentifikasiya olunmuş istifadəçilər server tərəfində məhdudiyyət olmadan ACME "acme_url" parametrini manipulyasiya edərək, bulud metadata xidmətlərinə qarşı backend sorğuları göndərə bilərdi. Təsirə məruz qalan qurumlar dərhal 1.9.2 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Lemur are affected by CVE-2026-55166?
This vulnerability affects Lemur versions prior to 1.9.2.
What action could an authenticated user perform by exploiting CVE-2026-55166?
An authenticated user could manipulate the ACME "acme_url" to send backend requests to internal services like cloud instance metadata.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.