PT-2026-98335 · Unknown · Lemonldap::Ng::Handler
CVE-2026-95811
·
Published
2026-09-25
·
Updated
2026-09-26
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Lemonldap::NG::Handler versions 2.0.0 through 2.16.9
Lemonldap::NG::Handler versions 2.17.0 through 2.21.5
Lemonldap::NG::Handler versions 2.22.0 through 2.23.3
Description
An issue exists where an equivalent spelling of a path can be used to bypass
locationRules restrictions. The handler matches regular expressions within locationRules against the REQUEST URI (the raw request line), whereas the web server routes based on a path that has already been normalized and percent-decoded. Consequently, a request that utilizes percent-encoding of path characters, inserts dot segments, or employs double slashes can reach a protected resource via a URI that does not match any defined rule. In such cases, access is determined by the vhost's default rule. This allows the bypass of deny rules, identity and group conditions, as well as unprotect and skip rules, provided the vhost's default rule is more permissive than its other rules. An authenticated user can then access any URL that the locationRules were intended to restrict, limited to the permissions granted by the default rule.Recommendations
Update to version 2.16.10 or later for the 2.0.x branch.
Update to version 2.21.6 or later for the 2.17.x branch.
Update to version 2.23.4 or later for the 2.22.x branch.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lemonldap::Ng::Handler