Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-92289: LemonLDAP NG Portal 2.23.0‑2.23.3 may let attackers bypass login check
CVE-2026-92289 · published 5 days ago
Summary
The LemonLDAP NG Portal versions from 2.23.0 up to 2.23.3 do not correctly verify a secret when using the PKCE (Proof Key for Code Exchange) flow, allowing a public client to obtain an authentication token without proper proof. This could let an unauthorized user gain access to protected applications. Update the portal to version 2.23.4 or later and confirm the configuration follows the recommended security guidance.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | lemonldap-ng | All versions |
| Ubuntu:16.04:LTS | canonical | lemonldap-ng | All versions |
Original advisory text
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
[Unknown description]
References
- http://www.openwall.com/lists/oss-security/2026/09/25/2 URL
- https://security-tracker.debian.org/tracker/CVE-2026-92289 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-92289 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-92289 Third Party Advisory
- https://cpan.org/modules URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92289... Vendor Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92289 Vendor Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng Product
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719 Third Party Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-1390Weak Authentication
Timeline
Published24 Sep 2026
Updated28 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-92289 · NVD
CVE-2026-92289 · MITRE
DEBIAN-CVE-2026-92289 · OSV
UBUNTU-CVE-2026-92289 · OSV
CVE-2026-92289 · OSV
Track software like this
Free during beta