PT-2026-98320 · Unknown · Lemonldap::Ng::Portal

CVE-2026-92289

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lemonldap::NG::Portal versions 2.23.0 through 2.23.3
Description An issue exists where public Relying Parties in PKCE or secret mode can bypass Proof Key for Code Exchange (PKCE), a security extension for OAuth 2.0 that prevents authorization code injection. This occurs because the checkEndPointAuthenticationCredentials() function fails to verify the client secret. When oidcRPMetaDataOptionsRequirePKCE is set to 2, the authorization endpoint issues a code without a code challenge. Subsequently, the token() function allows the exchange if a challenge was stored or an authentication method was returned. Since checkEndPointAuthenticationCredentials() skips secret comparison for public Relying Parties, any Basic or form credential is accepted, and validatePKCEChallenge() passes due to the absence of a challenge or verifier. An attacker intercepting an authorization code can exchange it for access, ID, and refresh tokens by replaying the client id with an arbitrary secret.
Recommendations Update Lemonldap::NG::Portal to version 2.23.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92289

Affected Products

Lemonldap::Ng::Portal