Skip to content
Rota Nacional

Guides ·

CVE-2026-92288: OAuth2 introspection flaw in Lemonldap::NG::Portal

A security notice says OAuth2 tokens belonging to public relying parties may be inspected without authentication. The issue affects specified Lemonldap::NG::Portal versions; consult the original notice to confirm scope and recommended action.

The notice for CVE-2026-92288 describes a Lemonldap::NG::Portal flaw: OAuth2 tokens belonging to public relying parties may be inspected without authentication because the client secret is not verified. The material was posted to the oss-sec feed on September 24, 2026, by Timothy Legge; the feed record is dated September 25, 2026, and says the translation is automatic.

The affected ranges stated are versions 2.20.0 up to, but not including, 2.21.6, and versions 2.22.0 up to, but not including, 2.23.4. The available excerpt does not detail the fix or other exploitation conditions. Do not assume an installation is protected without checking its version and the official guidance.

To assess the risk, identify which versions are in use and whether any relying parties are public. Compare those details with the original notice and consult the project’s official documentation to confirm the stated fix and update procedure. Verify the installed version after making changes.

If you use AI to study the notice or prepare an analysis, share only necessary information and remove names, contact details, and other personal data. Do not submit client secrets, tokens, credentials, or sensitive configuration. Verify technical conclusions against official sources before acting.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free