CVE-2026-19349
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends.
Before redirecting to the identity provider, extractFormInfo() creates the state session with the positional call `getApacheSession( undef, 1, 0, 'GitHubState' )`. getApacheSession() takes a session id followed by a named argument hash, so the trailing arguments become that hash, `kind` defaults to SSO, and the state is written to the global session storage as a regular SSO session. Its identifier is handed to the unauthenticated visitor as the state parameter of the redirection URL.
Leer descripción completaMostrar menos
Any visitor who reaches the GitHub or LinkedIn endpoint can replay that identifier as a session cookie and obtain a valid SSO session without authenticating. The session holds neither _user nor authenticationLevel, which the shipped bootstrap configuration accepts because it grants virtual hosts a "default => accept" access rule; deployments whose rules test the user or require an authentication level are less exposed. Only configurations with the GitHub or LinkedIn authentication module enabled are affected.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.82%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access90 % - Impacto secundario
T1556Modify Authentication Processdefense impairment · persistence · credential access75 %
AV:N, PR:N, UI:N indica explotación remota sin autenticación (T1190). El bypass OAuth2 permite obtener sesión SSO válida sin credenciales (T1078: Valid Accounts). Posible manipulación de autenticación en backend (T1556).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-305, CWE-628
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-19349",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-19349",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-17T16:38:49.938313Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng",
"modules": [
"Lemonldap::NG::Portal"
],
"versions": [
{
"status": "affected",
"version": "2.0.0",
"lessThan": "2.16.9",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.17.0",
"lessThan": "2.21.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.22.0",
"lessThan": "2.23.3",
"versionType": "custom"
}
],
"packageURL": "pkg:cpan/Lemonldap-NG-Portal",
"packageName": "Lemonldap-NG-Portal",
"programFiles": [
"lib/Lemonldap/NG/Portal/Auth/GitHub.pm",
"lib/Lemonldap/NG/Portal/Auth/LinkedIn.pm"
],
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "Lemonldap::NG::Portal::Auth::GitHub::extractFormInfo"
},
{
"name": "Lemonldap::NG::Portal::Auth::LinkedIn::extractFormInfo"
}
]
}
]
}
],
"published": "2026-08-16T14:16:54.720",
"references": [
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.16.9",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.5",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.3",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/08/16/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-305"
},
{
"lang": "en",
"value": "CWE-628"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends.\n\nBefore redirecting to the identity provider, extractFormInfo() creates the state session with the positional call `getApacheSession( undef, 1, 0, 'GitHubState' )`. getApacheSession() takes a session id followed by a named argument hash, so the trailing arguments become that hash, `kind` defaults to SSO, and the state is written to the global session storage as a regular SSO session. Its identifier is handed to the unauthenticated visitor as the state parameter of the redirection URL.\n\nAny visitor who reaches the GitHub or LinkedIn endpoint can replay that identifier as a session cookie and obtain a valid SSO session without authenticating. The session holds neither _user nor authenticationLevel, which the shipped bootstrap configuration accepts because it grants virtual hosts a \"default => accept\" access rule; deployments whose rules test the user or require an authentication level are less exposed. Only configurations with the GitHub or LinkedIn authentication module enabled are affected."
}
],
"lastModified": "2026-08-26T16:51:19.490",
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}