Open Redirect Vulnerability in LemonLDAP-NG Portal by LemonLDAP
CVE-2026-12804
5.3MEDIUM
What is CVE-2026-12804?
A security flaw has been identified in the LemonLDAP-NG application, specifically within the SAML Common Domain Cookie Endpoint component. This vulnerability allows an attacker to manipulate a specific URL argument, leading to an open redirect scenario. The exploitation of this issue can be executed remotely, which poses a significant risk if left unaddressed. The vendor has been notified about the vulnerability's details; however, no response has been received regarding a fix or mitigation strategy. As this exploit is now publicly available, it is critical for users to be aware of the potential risks associated with this version of LemonLDAP-NG.
Affected Version(s)
lemonldap-ng 2.0
lemonldap-ng 2.1
lemonldap-ng 2.2
