CVE-2026-44305General

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a man-in-the-middle attacker positioned between Lemur and the LDAP server to intercept all authentication credentials. This vulnerability is fixed in 1.9.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 105-1205-13
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
General1
2026-05-131
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44305 TLS Certificate Verification Bypass in Lemur LDAP Authentication Prior to 1.9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44305

    Post summary

    The post announces CVE-2026-44305, describing a TLS certificate verification bypass in Lemur LDAP authentication before version 1.9.0, and directs readers to a vulnerability details page.

    0000062
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44305 Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TL… https://www.cve.org/CVERecord?id=CVE-2026-44305

    Post summary

    The text references CVE-2026-44305, indicating a TLS handling flaw in Lemur's LDAP authentication module prior to version 1.9.0; no exploit, patch, or exploitation evidence is presented.

    0000058
    57.5K followersView on X

Explore more