CVE-2026-92288
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party.
checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method deduced from the request, client_secret_basic or client_secret_post. introspection() rejects a caller only when that method is missing or none, so a request carrying a public client_id and an arbitrary or empty secret passes the endpoint's authentication check.
Leer descripción completaMostrar menos
An attacker who holds an access token and knows the client_id of any public Relying Party can confirm the token is active and read its metadata, including scope, audience, expiry and the sub claim. The sub claim is computed with the calling Relying Party's user identifier attribute, so an attacker can translate a user identifier from one Relying Party to another, defeating per-client and pseudonymous identifiers.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.37%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access90 % - Impacto principal
T1078.004Cloud Accountsstealth · persistence · privilege escalation · initial access85 %
Vector CVSS AV:N sin autenticación indica explotación remota (T1190). Introspección OAuth2 sin verificación de secreto permite validar tokens y leer metadatos (scopes, sub claim), traduciéndose en acceso a identidades de usuario (T1078.004) y manipulación de autenticación OAuth (T1556.006).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-1390
Referencias
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3721
- http://www.openwall.com/lists/oss-security/2026/09/25/1
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-92288",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-92288",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-09-25T15:47:19.676630Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng",
"modules": [
"Lemonldap::NG::Portal"
],
"versions": [
{
"status": "affected",
"version": "2.20.0",
"lessThan": "2.21.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.22.0",
"lessThan": "2.23.4",
"versionType": "custom"
}
],
"packageURL": "pkg:cpan/Lemonldap-NG-Portal",
"packageName": "Lemonldap-NG-Portal",
"programFiles": [
"lib/Lemonldap/NG/Portal/Lib/OpenIDConnect.pm",
"lib/Lemonldap/NG/Portal/Issuer/OpenIDConnect.pm"
],
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "Lemonldap::NG::Portal::Lib::OpenIDConnect::checkEndPointAuthenticationCredentials"
},
{
"name": "Lemonldap::NG::Portal::Issuer::OpenIDConnect::introspection"
}
]
}
]
}
],
"published": "2026-09-25T01:16:48.820",
"references": [
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3721",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/25/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-1390"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party.\n\ncheckEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method deduced from the request, client_secret_basic or client_secret_post. introspection() rejects a caller only when that method is missing or none, so a request carrying a public client_id and an arbitrary or empty secret passes the endpoint's authentication check.\n\nAn attacker who holds an access token and knows the client_id of any public Relying Party can confirm the token is active and read its metadata, including scope, audience, expiry and the sub claim. The sub claim is computed with the calling Relying Party's user identifier attribute, so an attacker can translate a user identifier from one Relying Party to another, defeating per-client and pseudonymous identifiers."
}
],
"lastModified": "2026-09-25T16:17:29.543",
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}