THREAT OPS › Threat News › [GHSA] GHSA-6c8m-q6g9-vrw3 (high) — Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
[GHSA] GHSA-6c8m-q6g9-vrw3 (high) — Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
GHSA-6c8m-q6g9-vrw3 Severity: high CVE: CVE-2026-71307
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
### Summary Lemur's destination read endpoints -- `GET /api/1/destinations` and `GET /api/1/destinations/<id>` -- return the full set of stored plugin option values to any authenticated user, w
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-71307cve
Original source: https://github.com/advisories/GHSA-6c8m-q6g9-vrw3