CVE-2026-44304

HIGH LAB

Lemur: LDAP Filter Injection enables post-authentication privilege escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-44304. PoCs published by dwisiswant0.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-44304, an LDAP filter injection vulnerability in Netflix Lemur versions prior to 1.9.0. The exploit demonstrates privilege escalation by injecting LDAP metacharacters into the username field during authentication, bypassing group-membership checks to gain admin roles.

Description

Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group membership queries and escalate their privileges to administrator. This vulnerability is fixed in 1.9.0.

Exploits (1)

github WORKING POC 1 stars
by dwisiswant0 · pythonpoc
https://github.com/dwisiswant0/neo-pocs/tree/master/2026/CVE-2026-44304

This repository contains a functional exploit for CVE-2026-44304, an LDAP filter injection vulnerability in Netflix Lemur versions prior to 1.9.0. The exploit demonstrates privilege escalation by injecting LDAP metacharacters into the username field during authentication, bypassing group-membership checks to gain admin roles.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Netflix Lemur < 1.9.0
Auth required
Prerequisites: valid LDAP user account · network access to Lemur web interface · LDAP authentication enabled in Lemur
devstral-2 · analyzed May 14, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0002
EPSS Percentile 6.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull osixia/openldap:1.5.0

Details

CWE
CWE-90
Status published
Products (2)
Netflix/lemur < 1.9.0
pypi/lemur 0 - 1.9.0PyPI
Published May 12, 2026
Tracked Since May 13, 2026