THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pxmc-2ffp-8j67 (high) — Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

[GHSA] GHSA-pxmc-2ffp-8j67 (high) — Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

medgithub_advisoriesPublished 2026-08-18

GHSA-pxmc-2ffp-8j67 Severity: high CVE: CVE-2026-71417

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

## Summary

Repo under test: https://github.com/Netflix/lemur

`PUT /api/1/certificates/<id>/revoke` authorizes the caller against the *Lemur database row* (creator == current user, or `CertificatePermission` over the row's roles) rath

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pxmc-2ffp-8j67