Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-92289: LemonLDAP NG Portal 2.23.0‑2.23.3 may let attackers bypass login check

CVE-2026-92289 · published 5 days ago
Summary

The LemonLDAP NG Portal versions from 2.23.0 up to 2.23.3 do not correctly verify a secret when using the PKCE (Proof Key for Code Exchange) flow, allowing a public client to obtain an authentication token without proper proof. This could let an unauthorized user gain access to protected applications. Update the portal to version 2.23.4 or later and confirm the configuration follows the recommended security guidance.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian lemonldap-ng All versions
Ubuntu:16.04:LTS canonical lemonldap-ng All versions
Original advisory text
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
[Unknown description]
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-1390Weak Authentication
Timeline
Published24 Sep 2026
Updated28 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta