Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-92288PATCHED

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party

Description

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method deduced from the request, client_secret_basic or client_secret_post. introspection() rejects a caller only when that method is missing or none, so a request carrying a public client_id and an arbitrary or empty secret passes the endpoint's authentication check. An attacker who holds an access token and knows the client_id of any public Relying Party can confirm the token is active and read its metadata, including scope, audience, expiry and the sub claim. The sub claim is computed with the calling Relying Party's user identifier attribute, so an attacker can translate a user identifier from one Relying Party to another, defeating per-client and pseudonymous identifiers.

References

  • https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719(issue-tracking)
  • https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3721(issue-tracking)
  • https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4(release-notes)
  • https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6(release-notes)

Related News (2 articles)

Tier C
VulDB3d ago
CVE-2026-92288 | Lemonldap::NG up to 2.21.5/2.23.3 Token Introspection checkEndPointAuthenticationCredentials improper authentication
→ No new info (linked only)
Tier C
oss-security3d ago
CVE-2026-92288: Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.21.62.23.4
CWECWE-1390
PublishedSep 25, 2026
Last enriched2d ago
Trending Score44
Source articles2
Independent2
Info Completeness6/14
Missing: vendor, product, cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 25, 2026
Discovered by ZDM
Sep 25, 2026
Patch Available
Sep 25, 2026