Credential and key exposure via SSRF and IDOR
Published Aug 18, 2026 · Updated Aug 18, 2026
SSRF and authorization bypass in Netflix Lemur before 1.9.2 allow remote authenticated users to read cloud credentials and private keys. The ACME handler accepts a user-influenced acme_url and passes it to ClientV2.get_directory without effective destination restriction, allowing backend requests to reach instance-metadata or internal services; the key-fetch view also skips CertificatePermission when the caller matches cert.user, so the original creator can still export a certificate's private key after ownership changes. Exploitation requires an authenticated Lemur account and, for the key-access path, creator status on the certificate; the advisory states that pre-1.9.2 audit data did not clearly distinguish creator-based key exports after transfer.
Summary
What happened
SSRF and authorization bypass in Netflix Lemur before 1.9.2 allow remote authenticated users to read cloud credentials and private keys. The ACME handler accepts a user-influenced acme_url and passes it to ClientV2.get_directory without effective destination restriction, allowing backend requests to reach instance-metadata or internal services; the key-fetch view also skips CertificatePermission when the caller matches cert.user, so the original creator can still export a certificate's private key after ownership changes. Exploitation requires an authenticated Lemur account and, for the key-access path, creator status on the certificate; the advisory states that pre-1.9.2 audit data did not clearly distinguish creator-based key exports after transfer.
The record
- CVE
- CVE-2026-55166
- Published
- Aug 18, 2026
- Updated
- Aug 18, 2026
- Vendor
- Netflix
- Product
- Lemur
- Classifications
- CWE-918, CWE-285, CWE-639, T1552.005
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- Aug 18, 2026CVE publishedPublication date reported by the CVE source.
- Aug 18, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=< 1.9.2
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- GHSA-v2wp-frmc-5q3v proof of concept and walkthroughproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo