Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92288— Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party

Quick assessment

Affected
CVE-2026-92288
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Lemonldap::NG::Portal 2.20.0 至 2.21.5 版本(不含 2.21.6),以及 2.22.0 至 2.23.3 版本(不含 2.23.4)的 Perl 版本存在安全漏洞,允许未经认证的 OAuth2 令牌检查(token introspection)。原因在于 函数未对标记为“公开”(public)的依赖方(Relying Party)客户端密钥进行验证。 具体而言, 函数对于标记为公开的依赖方会跳过客户端密钥(client secret)的比对,但仍返回从请求中推断出的认证方法(即

AI Predicted 7.5 Difficulty: Easy EPSS 0.37% · P28

Possible ATT&CK Techniques 1 AI

T1556 · Modify Authentication Process

Affected Version Matrix 2

VendorProduct Version RangeStatus
None None 2.20.0< 2.21.6 affected
2.22.0< 2.23.4 affected

I. Basic Information for CVE-2026-92288

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party
Source: CVE Program / CVE List V5
Vulnerability Description
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method deduced from the request, client_secret_basic or client_secret_post. introspection() rejects a caller only when that method is missing or none, so a request carrying a public client_id and an arbitrary or empty secret passes the endpoint's authentication check. An attacker who holds an access token and knows the client_id of any public Relying Party can confirm the token is active and read its metadata, including scope, audience, expiry and the sub claim. The sub claim is computed with the calling Relying Party's user identifier attribute, so an attacker can translate a user identifier from one Relying Party to another, defeating per-client and pseudonymous identifiers.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1390
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 2.20.0 ~ 2.21.6 -

II. Public POCs for CVE-2026-92288

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92288

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-92288 (1)

Vendor Advisories for CVE-2026-92288 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92288

No comments yet


Leave a comment