Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-92288: LemonLDAP NG Portal permits unauthenticated token introspection
CVE-2026-92288 · published 5 days ago
Summary
Certain older versions of LemonLDAP NG Portal (2.20.0 up to 2.21.5 and 2.22.0 up to 2.23.3) fail to verify a client’s secret when processing OAuth2 token introspection requests. This lets anyone query token details without logging in, potentially exposing user information. Upgrade to version 2.21.6, 2.23.4 or later, or apply the vendor’s patch to fix the check.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | lemonldap-ng | All versions |
| Ubuntu:16.04:LTS | canonical | lemonldap-ng | All versions |
Original advisory text
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party
[Unknown description]
References
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4 Vendor Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719 Third Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3721 Third Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/25/1 URL
- https://security-tracker.debian.org/tracker/CVE-2026-92288 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-92288 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-92288 Third Party Advisory
- https://cpan.org/modules URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92288... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92288 Vendor Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng Product
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-1390Weak Authentication
Timeline
Published24 Sep 2026
Updated28 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-92288 · NVD
CVE-2026-92288 · MITRE
DEBIAN-CVE-2026-92288 · OSV
UBUNTU-CVE-2026-92288 · OSV
CVE-2026-92288 · OSV
Track software like this
Free during beta