PT-2026-98335 · Unknown · Lemonldap::Ng::Handler

CVE-2026-95811

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lemonldap::NG::Handler versions 2.0.0 through 2.16.9 Lemonldap::NG::Handler versions 2.17.0 through 2.21.5 Lemonldap::NG::Handler versions 2.22.0 through 2.23.3
Description An issue exists where an equivalent spelling of a path can be used to bypass locationRules restrictions. The handler matches regular expressions within locationRules against the REQUEST URI (the raw request line), whereas the web server routes based on a path that has already been normalized and percent-decoded. Consequently, a request that utilizes percent-encoding of path characters, inserts dot segments, or employs double slashes can reach a protected resource via a URI that does not match any defined rule. In such cases, access is determined by the vhost's default rule. This allows the bypass of deny rules, identity and group conditions, as well as unprotect and skip rules, provided the vhost's default rule is more permissive than its other rules. An authenticated user can then access any URL that the locationRules were intended to restrict, limited to the permissions granted by the default rule.
Recommendations Update to version 2.16.10 or later for the 2.0.x branch. Update to version 2.21.6 or later for the 2.17.x branch. Update to version 2.23.4 or later for the 2.22.x branch.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95811

Affected Products

Lemonldap::Ng::Handler