Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55164

Опубликовано: 18 авг. 2026
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Because no before_update listener ran, administrator-initiated password changes through PUT /api/1/users/ were committed as plaintext. The affected user could no longer authenticate normally because bcrypt verification received an unhashed value. A database, backup, replica, query-log, or administrative read compromise exposed immediately usable credentials without offline cracking. The fix registers hashing for before_update and avoids rehashing values that already have a bcrypt prefix. This issue is fixed in version 1.9.2.

EPSS

Процентиль: 22%
0.00292
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-256

Связанные уязвимости

CVSS3: 4.9
debian
около 1 месяца назад

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.se ...

CVSS3: 4.9
github
3 месяца назад

Lemur user-update path stores plaintext passwords

EPSS

Процентиль: 22%
0.00292
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-256