THREAT OPS › Threat News › [GHSA] GHSA-pxmc-2ffp-8j67 (high) — Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
[GHSA] GHSA-pxmc-2ffp-8j67 (high) — Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
GHSA-pxmc-2ffp-8j67 Severity: high CVE: CVE-2026-71417
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
## Summary
Repo under test: https://github.com/Netflix/lemur
`PUT /api/1/certificates/<id>/revoke` authorizes the caller against the *Lemur database row* (creator == current user, or `CertificatePermission` over the row's roles) rath
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-71417cve
Original source: https://github.com/advisories/GHSA-pxmc-2ffp-8j67