Open Redirect Vulnerability in LemonLDAP-NG Portal by LemonLDAP
CVE-2026-12804

5.3MEDIUM

Key Information:

Vendor

LemonLDAP

Vendor
CVE Published:
21 June 2026

What is CVE-2026-12804?

A security flaw has been identified in the LemonLDAP-NG application, specifically within the SAML Common Domain Cookie Endpoint component. This vulnerability allows an attacker to manipulate a specific URL argument, leading to an open redirect scenario. The exploitation of this issue can be executed remotely, which poses a significant risk if left unaddressed. The vendor has been notified about the vulnerability's details; however, no response has been received regarding a fix or mitigation strategy. As this exploit is now publicly available, it is critical for users to be aware of the potential risks associated with this version of LemonLDAP-NG.

Affected Version(s)

lemonldap-ng 2.0

lemonldap-ng 2.1

lemonldap-ng 2.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geochen (VulDB User)
VulDB CNA Team
.