{"id":"CVE-2026-92289","summary":"Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in \"PKCE or secret\" mode because checkEndPointAuthenticationCredentials does not verify the client secret","details":"Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in \"PKCE or secret\" mode because checkEndPointAuthenticationCredentials does not verify the client secret.\n\nWith oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when the request carries no code_challenge, and token() admits the exchange as long as a challenge was stored or an authentication method was returned for the caller. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the method deduced from the request, so any Basic or form credential satisfies the secret branch. validatePKCEChallenge() then passes, because neither a challenge nor a verifier is present.\n\nAn attacker who intercepts an authorization code issued to a public Relying Party can exchange it for the user's access, ID and refresh tokens by replaying the client_id with an arbitrary secret, which is the attack PKCE prevents. Dynamic client registration creates every Relying Party in this mode.","modified":"2026-09-28T03:48:35.723406113Z","published":"2026-09-25T00:15:49.826Z","database_specific":{"cwe_ids":["CWE-1390"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92289.json","cna_assigner":"CPANSec"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/25/2"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92289.json"},{"type":"ADVISORY","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92289"},{"type":"REPORT","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719"},{"type":"PACKAGE","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng","events":[{"introduced":"b33d2e2346596048fb83d4d98bb758b4e1b8e07d"},{"fixed":"6602ae87a262e28539d54454ec99622c75141cb5"}],"database_specific":{"extracted_events":[{"introduced":"2.23.0"},{"fixed":"2.23.4"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v2.23.3","v2.23.2","v2.23.1","v2.23.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92289.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}