<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:46:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355200</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355200</link>
      <description>EUVD-2026-355200</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355200</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48508</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48508</link>
      <description>&lt;p&gt;Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are unset because both flags default to False. Flask-Principal Permission.allows() returns True when self.needs is empty, so the .can() authorization gate permits every authenticated identity, including the read-only role. A read-only user can access POST /api/1/authorities, POST /api/1/certificates/upload, POST /api/1/pending_certificates//upload, POST /api/1/notifications, PUT or DELETE /api/1/notifications/, and POST /api/1/domains to create root Certificate Authorities, upload arbitrary certificates, create or edit notifications that reach an SSRF sink, and create domain entries. Explicitly setting either flag to False continues to opt into the permissive behavior. This issue is fixed in version 1.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are unset because both flags default to False. Flask-Principal Permission.allows() returns True when self.needs is empty, so the .can() authorization gate permits every authenticated identity, including the read-only role. A read-only user can access POST /api/1/authorities, POST /api/1/certificates/upload, POST /api/1/pending_certificates//upload, POST /api/1/notifications, PUT or DELETE /api/1/notifications/, and POST /api/1/domains to create root Certificate Authorities, upload arbitrary certificates, create or edit notifications that reach an SSRF sink, and create domain entries. Explicitly setting either flag to False continues to opt into the permissive behavior. This issue is fixed in version 1.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48508</guid>
    </item>
    <item>
      <title>GHSA-qcqw-jwxc-2hqg — Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qcqw-jwxc-2hqg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`StrictRolePermission` and `AuthorityCreatorPermission` in `lemur/auth/permissions.py` call `flask_principal.Permission.__init__()` with zero `Need`s when their config flags are unset. Both flags defaulted to `False` in code prior to the fix, so this was the state of any Lemur install that hadn&amp;#39;t explicitly opted in.&lt;/p&gt;
&lt;p&gt;Flask-Principal&amp;#39;s `Permission.allows()` returns `True` whenever `self.needs` is empty. The `.can()` gate therefore passes for every authenticated identity, including the lowest-privilege role Lemur ships (`read-only`).&lt;/p&gt;
&lt;p&gt;A user holding only `read-only` can create root Certificate Authorities, create and edit notifications (an SSRF sink), create domain entries, and upload arbitrary certificates. These classes are the sole authorization check on those endpoints.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;```python
# lemur/auth/permissions.py
class AuthorityCreatorPermission(Permission):
    def __init__(self):
        requires_admin = current_app.config.get(&amp;#34;ADMIN_ONLY_AUTHORITY_CREATION&amp;#34;, False)
        if requires_admin:
            super().__init__(RoleNeed(&amp;#34;admin&amp;#34;))
        else:
            super().__init__()              # empty Need set&lt;/p&gt;
&lt;p&gt;class StrictRolePermission(Permission):
    def __init__(self):
        strict_role_enforcement = current_app.config.get(&amp;#34;LEMUR_STRICT_ROLE_ENFORCEMENT&amp;#34;, False)
        if strict_role_enforcement:
            needs = [RoleNeed(&amp;#34;admin&amp;#34;), RoleNeed(&amp;#34;operator&amp;#34;)]
            super().__init__(*needs)
        else:
            super().__init__()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`StrictRolePermission` and `AuthorityCreatorPermission` in `lemur/auth/permissions.py` call `flask_principal.Permission.__init__()` with zero `Need`s when their config flags are unset. Both flags defaulted to `False` in code prior to the fix, so this was the state of any Lemur install that hadn&amp;#39;t explicitly opted in.&lt;/p&gt;
&lt;p&gt;Flask-Principal&amp;#39;s `Permission.allows()` returns `True` whenever `self.needs` is empty. The `.can()` gate therefore passes for every authenticated identity, including the lowest-privilege role Lemur ships (`read-only`).&lt;/p&gt;
&lt;p&gt;A user holding only `read-only` can create root Certificate Authorities, create and edit notifications (an SSRF sink), create domain entries, and upload arbitrary certificates. These classes are the sole authorization check on those endpoints.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;```python
# lemur/auth/permissions.py
class AuthorityCreatorPermission(Permission):
    def __init__(self):
        requires_admin = current_app.config.get(&amp;#34;ADMIN_ONLY_AUTHORITY_CREATION&amp;#34;, False)
        if requires_admin:
            super().__init__(RoleNeed(&amp;#34;admin&amp;#34;))
        else:
            super().__init__()              # empty Need set&lt;/p&gt;
&lt;p&gt;class StrictRolePermission(Permission):
    def __init__(self):
        strict_role_enforcement = current_app.config.get(&amp;#34;LEMUR_STRICT_ROLE_ENFORCEMENT&amp;#34;, False)
        if strict_role_enforcement:
            needs = [RoleNeed(&amp;#34;admin&amp;#34;), RoleNeed(&amp;#34;operator&amp;#34;)]
            super().__init__(*needs)
        else:
            super().__init__()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qcqw-jwxc-2hqg</guid>
    </item>
    <item>
      <title>PYSEC-2026-2588 — Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2588</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`StrictRolePermission` and `AuthorityCreatorPermission` in `lemur/auth/permissions.py` call `flask_principal.Permission.__init__()` with zero `Need`s when their config flags are unset. Both flags defaulted to `False` in code prior to the fix, so this was the state of any Lemur install that hadn&amp;#39;t explicitly opted in.&lt;/p&gt;
&lt;p&gt;Flask-Principal&amp;#39;s `Permission.allows()` returns `True` whenever `self.needs` is empty. The `.can()` gate therefore passes for every authenticated identity, including the lowest-privilege role Lemur ships (`read-only`).&lt;/p&gt;
&lt;p&gt;A user holding only `read-only` can create root Certificate Authorities, create and edit notifications (an SSRF sink), create domain entries, and upload arbitrary certificates. These classes are the sole authorization check on those endpoints.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;```python
# lemur/auth/permissions.py
class AuthorityCreatorPermission(Permission):
    def __init__(self):
        requires_admin = current_app.config.get(&amp;#34;ADMIN_ONLY_AUTHORITY_CREATION&amp;#34;, False)
        if requires_admin:
            super().__init__(RoleNeed(&amp;#34;admin&amp;#34;))
        else:
            super().__init__()              # empty Need set&lt;/p&gt;
&lt;p&gt;class StrictRolePermission(Permission):
    def __init__(self):
        strict_role_enforcement = current_app.config.get(&amp;#34;LEMUR_STRICT_ROLE_ENFORCEMENT&amp;#34;, False)
        if strict_role_enforcement:
            needs = [RoleNeed(&amp;#34;admin&amp;#34;), RoleNeed(&amp;#34;operator&amp;#34;)]
            super().__init__(*needs)
        else:
            super().__init__()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lemur&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`StrictRolePermission` and `AuthorityCreatorPermission` in `lemur/auth/permissions.py` call `flask_principal.Permission.__init__()` with zero `Need`s when their config flags are unset. Both flags defaulted to `False` in code prior to the fix, so this was the state of any Lemur install that hadn&amp;#39;t explicitly opted in.&lt;/p&gt;
&lt;p&gt;Flask-Principal&amp;#39;s `Permission.allows()` returns `True` whenever `self.needs` is empty. The `.can()` gate therefore passes for every authenticated identity, including the lowest-privilege role Lemur ships (`read-only`).&lt;/p&gt;
&lt;p&gt;A user holding only `read-only` can create root Certificate Authorities, create and edit notifications (an SSRF sink), create domain entries, and upload arbitrary certificates. These classes are the sole authorization check on those endpoints.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;```python
# lemur/auth/permissions.py
class AuthorityCreatorPermission(Permission):
    def __init__(self):
        requires_admin = current_app.config.get(&amp;#34;ADMIN_ONLY_AUTHORITY_CREATION&amp;#34;, False)
        if requires_admin:
            super().__init__(RoleNeed(&amp;#34;admin&amp;#34;))
        else:
            super().__init__()              # empty Need set&lt;/p&gt;
&lt;p&gt;class StrictRolePermission(Permission):
    def __init__(self):
        strict_role_enforcement = current_app.config.get(&amp;#34;LEMUR_STRICT_ROLE_ENFORCEMENT&amp;#34;, False)
        if strict_role_enforcement:
            needs = [RoleNeed(&amp;#34;admin&amp;#34;), RoleNeed(&amp;#34;operator&amp;#34;)]
            super().__init__(*needs)
        else:
            super().__init__()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2588</guid>
    </item>
  </channel>
</rss>
