Executive brief
Netflix Lemur, a certificate management framework, contains a flaw where certain security checks were disabled by default. This allows any logged-in user, even those with "read-only" access, to perform administrative actions such as creating root Certificate Authorities, uploading certificates, and modifying system notifications. An attacker could use this to issue fraudulent certificates or gain control over the organization's digital trust infrastructure.
Technical details
An authorization bypass exists in Lemur's 'StrictRolePermission' and 'AuthorityCreatorPermission' classes within 'lemur/auth/permissions.py'. These classes utilize Flask-Principal for access control; however, when specific configuration flags (ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT) are unset or False, the permission objects are initialized with an empty set of 'Needs'. Because Flask-Principal's 'Permission.allows()' returns True for empty requirement sets, any authenticated user—including those with the 'read-only' role—can bypass authorization gates on critical API endpoints. This allows unauthorized creation of root CAs, certificate uploads, and modification of notification settings (which can lead to SSRF). The vulnerability is remediated in version 1.9.1 by changing the default value of these configuration flags to True.
Affected products
- Netflix Lemur <= 1.9.0
Timeline
- 2026-05-28: disclosed: Vulnerability reported to vendor
- 2026-06-25: advisory: GitHub Advisory published