The notice for CVE-2026-92288 describes a Lemonldap::NG::Portal flaw: OAuth2 tokens belonging to public relying parties may be inspected without authentication because the client secret is not verified. The material was posted to the oss-sec feed on September 24, 2026, by Timothy Legge; the feed record is dated September 25, 2026, and says the translation is automatic.
The affected ranges stated are versions 2.20.0 up to, but not including, 2.21.6, and versions 2.22.0 up to, but not including, 2.23.4. The available excerpt does not detail the fix or other exploitation conditions. Do not assume an installation is protected without checking its version and the official guidance.
To assess the risk, identify which versions are in use and whether any relying parties are public. Compare those details with the original notice and consult the project’s official documentation to confirm the stated fix and update procedure. Verify the installed version after making changes.
If you use AI to study the notice or prepare an analysis, share only necessary information and remove names, contact details, and other personal data. Do not submit client secrets, tokens, credentials, or sensitive configuration. Verify technical conclusions against official sources before acting.