Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92289— Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret

Quick assessment

Affected
CVE-2026-92289
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Lemonldap::NG::Portal 版本 2.23.0 至 2.23.4(不包括 2.23.4)的 Perl 实现中,在“PKCE 或客户端密钥”(PKCE or secret)模式下,存在针对公开重定向方(Public Relying Parties)的 PKCE 绕过漏洞。原因是函数 未正确验证客户端密钥。 当配置项 设置为 2 时,授权端点即使在没有携带 的请求中也会颁发授权码;而 函数只要检测到此前存储了挑战(challenge)或为调用方返回了某种认证方法,就会允许进行令牌交换。 函数对标记为“公

AI Predicted 9.1 Difficulty: Easy EPSS 0.39% · P31

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
None None 2.23.0< 2.23.4 affected

I. Basic Information for CVE-2026-92289

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
Source: CVE Program / CVE List V5
Vulnerability Description
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when the request carries no code_challenge, and token() admits the exchange as long as a challenge was stored or an authentication method was returned for the caller. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the method deduced from the request, so any Basic or form credential satisfies the secret branch. validatePKCEChallenge() then passes, because neither a challenge nor a verifier is present. An attacker who intercepts an authorization code issued to a public Relying Party can exchange it for the user's access, ID and refresh tokens by replaying the client_id with an arbitrary secret, which is the attack PKCE prevents. Dynamic client registration creates every Relying Party in this mode.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1390
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 2.23.0 ~ 2.23.4 -

II. Public POCs for CVE-2026-92289

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92289

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-92289 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92289

No comments yet


Leave a comment