Authentication Bypass in Lemonldap::NG::Portal by OW2
CVE-2026-19349

Currently unrated

Key Information:

Status
Vendor
CVE Published:
16 August 2026

What is CVE-2026-19349?

The Lemonldap::NG::Portal features an authentication bypass vulnerability allowing unauthenticated access through OAuth2 state parameters. The exploit targets versions from 2.0.0 up to 2.16.9, from 2.17.0 up to 2.21.5, and from 2.22.0 up to 2.23.3. When visitors access the GitHub or LinkedIn authentication endpoints, they can impersonate a valid SSO session by replaying a stored state parameter. This vulnerability is particularly impactful in configurations with lenient access rules that accept default sessions without robust user verification, primarily affecting deployments using GitHub and LinkedIn for authentication.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.