External risk intelligence

LemonLDAP::NG OAuth2 Token Introspection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92288

Lemonldap::NG is an identity management and SSO portal designed to be exposed to the internet to handle authentication and token introspection for Relying Parties. As a public-facing authentication service, its endpoints are intended to be accessible to external clients and services, making this vulnerability directly reachable from the internet in standard deployments.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in LemonLDAP::NG, a system used for identity management and single sign-on. The issue allows unauthenticated attackers to potentially confirm the validity of access tokens and access their metadata, which could lead to the de-anonymization of users across different services. This matters because it weakens user privacy protections and pseudonymity.

  • Unauthenticated attackers can inspect access tokens.
  • It compromises user privacy and pseudonymous identifiers.
  • Verify relevance and assess exposure to user data.

Attack Path

How an attacker could exploit the issue

An attacker who possesses an active access token can bypass authentication checks on the OAuth2 token introspection endpoint. This is possible because the system does not properly verify the client secret for public Relying Parties, allowing an attacker to confirm a token's validity and retrieve its associated metadata. The vulnerability enables an attacker to correlate user identifiers across different Relying Parties, compromising per-client and pseudonymous identification.

  • No authentication required.
  • Introspection endpoint bypasses secret check.
  • User identifier correlation risk.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an unauthenticated attacker could confirm the activity and retrieve metadata of OAuth2 tokens by exploiting a flaw in how client secrets are handled for public Relying Parties. This could allow an attacker to translate user identifiers between different Relying Parties, compromising pseudonymous and per-client identifiers.

  • Token metadata and user identifiers.
  • Unauthenticated access to token introspection endpoint.
  • Defeat per-client and pseudonymous identifiers.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world responsibility for this vulnerability likely lies with the platform or infrastructure teams managing the LemonLDAP::NG deployment, in coordination with security and application owners who rely on its single sign-on (SSO) capabilities. The immediate practical step is to inventory all LemonLDAP::NG instances, determine their reachability and criticality, and identify the specific application or service owners who use them. Once confirmed, a risk-based remediation plan can be developed, prioritizing instances that are externally accessible and handle sensitive user data.

  • Platform/Infrastructure teams own the issue.
  • Verify LemonLDAP::NG instance reachability and criticality.
  • Plan remediation based on exposure and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LemonLDAP::NG?

LemonLDAP::NG is an open-source identity and access management solution. It provides single sign-on (SSO) capabilities and acts as an OAuth2 authorization server. Organizations use it to centralize authentication and token management, allowing users to log in once to access various interconnected web applications.

How does CVE-2026-92288 weaken security?

This vulnerability, classified as CWE-1390 (Enforcement of Privileges in an Authorization Process), stems from a failure to verify client secrets for public OAuth2 Relying Parties. By skipping this check, the system mistakenly treats unauthenticated requests as valid, allowing unauthorized parties to access sensitive metadata about tokens.

Can any request trigger this introspection flaw?

No. An attacker must possess an active access token and know the client_id of a public Relying Party to trigger the issue. The vulnerability specifically involves the misconfiguration of trust for public clients; it does not bypass security for clients that are properly configured to require a valid secret.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that LemonLDAP::NG is very likely to be affected because the software is designed to be internet-facing to handle authentication. Since these portals are typically exposed to support external clients, any instance reachable from the internet should be considered accessible to this threat.

What is the first step to address this CVE?

Begin by inventorying all LemonLDAP::NG instances in your environment to identify which are internet-facing. Coordinate with infrastructure and application teams to determine which services rely on the affected OAuth2 introspection features, then prioritize patching instances that handle sensitive user data or pseudonymous identifiers.

References