PT-2026-98319 · Unknown · Lemonldap::Ng::Portal

CVE-2026-92288

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lemonldap::NG::Portal versions 2.20.0 through 2.21.5 Lemonldap::NG::Portal versions 2.22.0 through 2.23.3
Description An issue exists in the OAuth2 token introspection process where the checkEndPointAuthenticationCredentials() function fails to verify the client secret for public Relying Parties. The function skips secret comparison for these parties but still returns the authentication method derived from the request, such as client secret basic or client secret post. Consequently, the introspection() function allows requests with a public client id and an empty or arbitrary secret to pass authentication. An attacker possessing an access token and the client id of a public Relying Party can verify if the token is active and access its metadata, including scope, audience, expiry, and the sub claim. This allows the translation of user identifiers between different Relying Parties, bypassing per-client and pseudonymous identifier protections.
Recommendations Update Lemonldap::NG::Portal versions 2.20.0 through 2.21.5 to version 2.21.6. Update Lemonldap::NG::Portal versions 2.22.0 through 2.23.3 to version 2.23.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92288

Affected Products

Lemonldap::Ng::Portal