« Volver al listado

CVE-2026-92288

Estado: AplazadaCrítica (9.1)—

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party.

checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method deduced from the request, client_secret_basic or client_secret_post. introspection() rejects a caller only when that method is missing or none, so a request carrying a public client_id and an arbitrary or empty secret passes the endpoint's authentication check.

Leer descripción completaMostrar menos

An attacker who holds an access token and knows the client_id of any public Relying Party can confirm the token is active and read its metadata, including scope, audience, expiry and the sub claim. The sub claim is computed with the calling Relying Party's user identifier attribute, so an attacker can translate a user identifier from one Relying Party to another, defeating per-client and pseudonymous identifiers.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N sin autenticación indica explotación remota (T1190). Introspección OAuth2 sin verificación de secreto permite validar tokens y leer metadatos (scopes, sub claim), traduciéndose en acceso a identidades de usuario (T1078.004) y manipulación de autenticación OAuth (T1556.006).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-92288",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-92288",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-25T15:47:19.676630Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng",
          "modules": [
            "Lemonldap::NG::Portal"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "2.20.0",
              "lessThan": "2.21.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.22.0",
              "lessThan": "2.23.4",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:cpan/Lemonldap-NG-Portal",
          "packageName": "Lemonldap-NG-Portal",
          "programFiles": [
            "lib/Lemonldap/NG/Portal/Lib/OpenIDConnect.pm",
            "lib/Lemonldap/NG/Portal/Issuer/OpenIDConnect.pm"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Lemonldap::NG::Portal::Lib::OpenIDConnect::checkEndPointAuthenticationCredentials"
            },
            {
              "name": "Lemonldap::NG::Portal::Issuer::OpenIDConnect::introspection"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-25T01:16:48.820",
  "references": [
    {
      "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3721",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/09/25/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1390"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party.\n\ncheckEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method deduced from the request, client_secret_basic or client_secret_post. introspection() rejects a caller only when that method is missing or none, so a request carrying a public client_id and an arbitrary or empty secret passes the endpoint's authentication check.\n\nAn attacker who holds an access token and knows the client_id of any public Relying Party can confirm the token is active and read its metadata, including scope, audience, expiry and the sub claim. The sub claim is computed with the calling Relying Party's user identifier attribute, so an attacker can translate a user identifier from one Relying Party to another, defeating per-client and pseudonymous identifiers."
    }
  ],
  "lastModified": "2026-09-25T16:17:29.543",
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}