CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8523

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret

CVE-2026-92289 affects Lemonldap::NG::Portal versions 2.23.0 through 2.23.3 for Perl, where the checkEndPointAuthenticationCredentials function fails to validate client secrets in PKCE or secret mode. This oversight enables proof key for code exchange (PKCE) bypass attacks against public relying parties. The vulnerability is resolved in version 2.23.4.

Why it matters: Organizations running affected Lemonldap::NG::Portal versions should upgrade immediately, as attackers can bypass authentication for public relying parties and potentially gain unauthorized access to protected resources.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary