Executive brief
Netflix Lemur, a tool used to manage and automate the creation of TLS certificates, contains a security flaw in its login system. An attacker with valid standard user credentials can manipulate the login process to trick the system into granting them administrator privileges. This would allow the attacker to access sensitive private keys, modify certificate authority configurations, and issue unauthorized security certificates.
Technical details
An LDAP injection vulnerability exists in Lemur's authentication module (lemur/auth/ldap.py) due to the use of unsanitized user input in Python string interpolation when constructing LDAP search filters. Specifically, the 'username' field provided during login is interpolated directly into the user lookup filter without escaping special characters. An attacker with valid LDAP credentials can inject LDAP metacharacters to manipulate group membership queries. This allows the attacker to be assigned privileged roles, such as administrator, granting them full access to certificates, private keys, and CA configurations. The issue is fixed in version 1.9.0 by implementing proper escaping using ldap.filter.escape_filter_chars().
Affected products
- Netflix Lemur < 1.9.0
Timeline
- 2026-04-28: advisory: GitHub advisory published by maintainers
- 2026-05-12: disclosed: CVE published to NVD
- 2026-05-12: patched: Fixed in version 1.9.0