External risk intelligence

LemonLDAP-NG PKCE Bypass Vulnerability In Public Relying Parties

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92289

Lemonldap::NG is an identity provider, web single sign-on solution, and access management portal. These systems are designed to be public-facing gateways to authenticate users and manage access to services, making them naturally internet-accessible components of an organization's identity infrastructure.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability affecting LemonLDAP::NG, an identity and access management system. The issue allows an attacker to bypass security checks, potentially enabling them to exchange authorization codes for user tokens, thereby gaining unauthorized access to sensitive information and services. The concern is centered on public-facing systems that manage user authentication and access control.

  • Public access systems may have compromised authentication.
  • Critical access control flaw could expose user data.
  • Confirm relevance; investigate potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise user accounts by bypassing security checks when an authorization code is issued. This bypass allows an attacker to exchange a stolen authorization code for sensitive tokens, effectively impersonating the user. This occurs when the system incorrectly handles requests without a code challenge or when a public party's secret is not properly verified.

  • No special access required.
  • Intercepting authorization codes.
  • Token theft and account takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to bypass authentication checks for public clients, enabling them to obtain access, ID, and refresh tokens for users. This may occur when the system is configured to require PKCE but misconfigures the `checkEndPointAuthenticationCredentials` function for public relying parties, allowing any arbitrary secret to satisfy authentication.

  • User tokens could be exposed.
  • Attackers can replay authorization codes.
  • Unauthorized access to user data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in LemonLDAP::NG affects its role as an identity and access management portal. The platform team or the team responsible for managing identity infrastructure is likely responsible for addressing this. The first practical step is to identify all instances of LemonLDAP::NG, confirm their exposure and criticality, and then coordinate remediation with the vendor or plan for mitigation.

  • Platform/Identity team owns the issue.
  • Verify LemonLDAP::NG instances and exposure.
  • Plan vendor coordination or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LemonLDAP::NG?

LemonLDAP::NG is a Perl-based identity and access management solution. It functions as a web single sign-on portal that authenticates users and governs their access to various internal and external services within an organization's identity infrastructure.

What is the security weakness in CVE-2026-92289?

This vulnerability is classified as CWE-1390, which involves weak authentication verification. Specifically, the portal fails to properly validate the client secret for public relying parties, effectively bypassing Proof Key for Code Exchange (PKCE) protections designed to secure the authentication process.

How can an attacker trigger this PKCE bypass?

An attacker triggers this by intercepting an authorization code issued to a public relying party. Because the system fails to enforce secret verification, the attacker can replay the client_id with an arbitrary secret to exchange that code for valid user tokens. Requests that include a valid code_challenge or non-public relying party configurations do not trigger this bypass.

Why should I care about this vulnerability?

According to Halo Surface Signal, LemonLDAP::NG is designed as an identity provider and is often deployed as an internet-facing gateway. If your instance is exposed to the internet, it is highly likely to be reachable by unauthorized actors who could attempt to impersonate users by stealing their tokens.

What are the first steps to address this flaw?

Begin by auditing your environment to locate all running instances of LemonLDAP::NG. Once identified, verify if you are using affected versions between 2.23.0 and 2.23.3. Coordinate with your identity or platform teams to prioritize upgrading to version 2.23.4 or higher to resolve the improper credential check.

References