Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-92288: LemonLDAP NG Portal permits unauthenticated token introspection

CVE-2026-92288 · published 5 days ago
Summary

Certain older versions of LemonLDAP NG Portal (2.20.0 up to 2.21.5 and 2.22.0 up to 2.23.3) fail to verify a client’s secret when processing OAuth2 token introspection requests. This lets anyone query token details without logging in, potentially exposing user information. Upgrade to version 2.21.6, 2.23.4 or later, or apply the vendor’s patch to fix the check.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian lemonldap-ng All versions
Ubuntu:16.04:LTS canonical lemonldap-ng All versions
Original advisory text
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party
[Unknown description]
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-1390Weak Authentication
Timeline
Published24 Sep 2026
Updated28 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta