CVE-2026-71308: Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

Published Aug 18, 2026
·
Updated

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetchobjects without a CertificatePermission check. Assigning those objects to Certificate.replaces invoked an append listener that disabled the victim certificate notifications and marked it as replaced. The victim was then excluded from getallpendingreissue, and certificaterotate could deploy the attacker certificate to endpoints serving the victim. An authenticated non-read-only user could target certificates for which the user had no ownership or role, suppress lifecycle automation, and cause fleet-wide TLS disruption or unauthorized substitution. The fix authorizes every referenced replacement certificate before mutation. This issue is fixed in version 1.9.3.

Affected Software

1 affected component
Lemur Lemur>0.5.0<1.9.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Lemur TLS certificate management to a version that resolves this vulnerability.

    Fixed in 1.9.3
  2. Compensating control

    Ensure the victim certificate is excluded from any pending reissue/rotation workflows (e.g., exclude it from get_all_pending_reissue) so certificate_rotate cannot deploy the attacker-controlled replacement to endpoints serving the victim certificate.

  3. Operational

    After upgrading, review for certificates that were marked as “replaced” via unchecked replaces/replacements and verify fleet TLS certificate rotation results are correct (especially where attacker certificates may have been substituted for victim certificates).

Event History

Aug 18, 2026
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which versions need remediation?

Lemur versions from 0.5.0 through 1.9.2 are affected. Version 1.9.3 fixes the issue by authorizing every certificate referenced as a replacement before mutation.

2

What access is required to exploit this?

An attacker needs an authenticated Lemur account that is not read-only. They do not need ownership of, or a role on, the certificates they target.

3

What operations can be abused and what is the impact?

The attacker can submit certificate create, upload, or edit requests containing replacement certificate identifiers. This can mark arbitrary victim certificates as replaced, disable their notifications, remove them from pending reissue processing, and potentially cause rotation to deploy the attacker's certificate to the victim's endpoints.

4

What should teams do if they are vulnerable?

Upgrade to version 1.9.3. The provided information does not describe an alternative mitigation for deployments that cannot immediately patch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203