PT-2026-98320 · Unknown · Lemonldap::Ng::Portal
CVE-2026-92289
·
Published
2026-09-25
·
Updated
2026-09-26
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Lemonldap::NG::Portal versions 2.23.0 through 2.23.3
Description
An issue exists where public Relying Parties in PKCE or secret mode can bypass Proof Key for Code Exchange (PKCE), a security extension for OAuth 2.0 that prevents authorization code injection. This occurs because the
checkEndPointAuthenticationCredentials() function fails to verify the client secret. When oidcRPMetaDataOptionsRequirePKCE is set to 2, the authorization endpoint issues a code without a code challenge. Subsequently, the token() function allows the exchange if a challenge was stored or an authentication method was returned. Since checkEndPointAuthenticationCredentials() skips secret comparison for public Relying Parties, any Basic or form credential is accepted, and validatePKCEChallenge() passes due to the absence of a challenge or verifier. An attacker intercepting an authorization code can exchange it for access, ID, and refresh tokens by replaying the client id with an arbitrary secret.Recommendations
Update Lemonldap::NG::Portal to version 2.23.4 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lemonldap::Ng::Portal