Path Bypass Vulnerability in Lemonldap::NG::Handler by OW2
CVE-2026-95811

Currently unrated

Key Information:

Vendor

OW2

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-95811?

A vulnerability in Lemonldap::NG::Handler allows attackers to bypass defined locationRules by crafting modified request URIs. The handler processes each virtual host's locationRules based on REQUEST_URI, which may not reflect the actual path being accessed due to percent-encoding and normalization. This can allow an authenticated user to access restricted resources if the default rule is more permissive than the specific locationRules intended to limit access. Consequently, sensitive data might be exposed when appropriate restrictions are circumvented.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deepseek agent, Linagora
.