PT-2026-98319 · Unknown · Lemonldap::Ng::Portal
CVE-2026-92288
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Lemonldap::NG::Portal versions 2.20.0 through 2.21.5
Lemonldap::NG::Portal versions 2.22.0 through 2.23.3
Description
An issue exists in the OAuth2 token introspection process where the
checkEndPointAuthenticationCredentials() function fails to verify the client secret for public Relying Parties. The function skips secret comparison for these parties but still returns the authentication method derived from the request, such as client secret basic or client secret post. Consequently, the introspection() function allows requests with a public client id and an empty or arbitrary secret to pass authentication. An attacker possessing an access token and the client id of a public Relying Party can verify if the token is active and access its metadata, including scope, audience, expiry, and the sub claim. This allows the translation of user identifiers between different Relying Parties, bypassing per-client and pseudonymous identifier protections.Recommendations
Update Lemonldap::NG::Portal versions 2.20.0 through 2.21.5 to version 2.21.6.
Update Lemonldap::NG::Portal versions 2.22.0 through 2.23.3 to version 2.23.4.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lemonldap::Ng::Portal