Skip to content

Lemur vulnerabilities

3 CVEs tracked

In our reporting, the Lemur vendor appears in the context of TLS certificate management. Key incidents involve authentication bypass mechanisms and URL redirection flaws. Defenders should pay close attention to CVE-2026-70667 (HTTP redirect following during revocation URL validation), CVE-2026-55165 ('alg' header manipulation in JWT verification), and CVE-2026-55163 (privilege escalation in role updates). It is recommended to urgently update the affected systems to versions 1.9.3 and 1.9.2 respectively.

Azərbaycanca: Hesabatlarımızda Lemur vendoru TLS sertifikatlarının idarə olunması kontekstində görünür. Əsas hadisələr autentifikasiya mexanizmlərindən yan keçmə və şəbəkə istiqamətləndirmə zəiflikləri ilə bağlıdır. Müdafiəçi CVE-2026-70667 (revocation URL yoxlamasında HTTP redirect izlənməsi), CVE-2026-55165 (JWT yoxlamasında 'alg' manipulyasiyası) və CVE-2026-55163 (rol yeniləmələrində səlahiyyət yüksəldilməsi) zəifliklərinə diqqət yetirməlidir. Təsirə məruz qalan sistemləri müvafiq olaraq 1.9.3 və 1.9.2 versiyalarına təcili yeniləmək tövsiyə olunur.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Lemur: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.