Skip to content
Rota Nacional

Cyber ·

CVE-2026-92289: PKCE bypass in Lemonldap::NG::Portal

A notice dated September 24, 2026 reports that, in “PKCE or secret” mode, missing client-secret verification may allow PKCE to be bypassed for public clients.

A CPAN Security Group notice, shared by Timothy Legge on September 24, 2026 and reproduced in the oss-sec feed, describes CVE-2026-92289 in Lemonldap-NG-Portal. The feed item is dated September 25, 2026. The reported issue occurs in “PKCE or secret” mode: missing verification of the client secret may allow PKCE to be bypassed for public Relying Parties.

The notice identifies versions from 2.23.0 up to, but not including, 2.23.4 as affected. To confirm the scope and remediation guidance, consult the original notice in the oss-sec archive and the package entry on MetaCPAN; compare that information with the version actually installed. The supplied text gives no further conditions or remediation details, so verify those points rather than assuming them.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free