# CVE-2026-55164

## Summary

- **CVE ID:** CVE-2026-55164
- **Severity:** MEDIUM
- **CVSS Score:** 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-256
- **Published:** Aug 18, 2026
- **Last Modified:** Aug 18, 2026

## Description

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Because no before_update listener ran, administrator-initiated password changes through PUT /api/1/users/ were committed as plaintext. The affected user could no longer authenticate normally because bcrypt verification received an unhashed value. A database, backup, replica, query-log, or administrative read compromise exposed immediately usable credentials without offline cracking. The fix registers hashing for before_update and avoids rehashing values that already have a bcrypt prefix. This issue is fixed in version 1.9.2.

## Affected Products

- Netflix — lemur (< 1.9.2)

## References

- [CNA](https://github.com/Netflix/lemur/security/advisories/GHSA-q437-g7fv-2jvv)
- [CNA](https://github.com/Netflix/lemur/commit/221c6d7275ac667bb8898ab48d2b96926a89c1c4)
- [CNA](https://github.com/Netflix/lemur/releases/tag/v1.9.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._