Authentication Bypass in Lemonldap::NG::Portal by OW2
CVE-2026-19349
Currently unrated
What is CVE-2026-19349?
The Lemonldap::NG::Portal features an authentication bypass vulnerability allowing unauthenticated access through OAuth2 state parameters. The exploit targets versions from 2.0.0 up to 2.16.9, from 2.17.0 up to 2.21.5, and from 2.22.0 up to 2.23.3. When visitors access the GitHub or LinkedIn authentication endpoints, they can impersonate a valid SSO session by replaying a stored state parameter. This vulnerability is particularly impactful in configurations with lenient access rules that accept default sessions without robust user verification, primarily affecting deployments using GitHub and LinkedIn for authentication.
