OAuth2 Token Introspection Vulnerability in Lemonldap::NG::Portal by OW2
CVE-2026-92288
Currently unrated
What is CVE-2026-92288?
A vulnerability in Lemonldap::NG::Portal allows unauthenticated OAuth2 token introspection due to the 'checkEndPointAuthenticationCredentials' function failing to properly verify client secrets for public Relying Parties. This may enable attackers to verify the active status of access tokens and access sensitive metadata, such as scope, audience, expiry, and user identifiers attributed by the calling Relying Party. Consequently, this issue poses significant risks in user privacy and system security as it allows unauthorized insight into token details without necessitating appropriate authentication.
