OAuth2 Token Introspection Vulnerability in Lemonldap::NG::Portal by OW2
CVE-2026-92288

Currently unrated

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-92288?

A vulnerability in Lemonldap::NG::Portal allows unauthenticated OAuth2 token introspection due to the 'checkEndPointAuthenticationCredentials' function failing to properly verify client secrets for public Relying Parties. This may enable attackers to verify the active status of access tokens and access sensitive metadata, such as scope, audience, expiry, and user identifiers attributed by the calling Relying Party. Consequently, this issue poses significant risks in user privacy and system security as it allows unauthorized insight into token details without necessitating appropriate authentication.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.