THREAT OPS › Threat News › [GHSA] GHSA-g7p5-89mh-248h (medium) — Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
[GHSA] GHSA-g7p5-89mh-248h (medium) — Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
GHSA-g7p5-89mh-248h Severity: medium CVE: CVE-2026-71317
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
## Summary
Repo under test: https://github.com/Netflix/lemur
When `ADMIN_ONLY_AUTHORITY_CREATION=False` (an explicitly supported and documented configuration), `POST /api/1/authorities` with `type=subca` never verifies that the caller holds `AuthorityPermis
Indicators of compromise
- CVE-2026-71317cve
Original source: https://github.com/advisories/GHSA-g7p5-89mh-248h