Path Bypass Vulnerability in Lemonldap::NG::Handler by OW2
CVE-2026-95811
Currently unrated
What is CVE-2026-95811?
A vulnerability in Lemonldap::NG::Handler allows attackers to bypass defined locationRules by crafting modified request URIs. The handler processes each virtual host's locationRules based on REQUEST_URI, which may not reflect the actual path being accessed due to percent-encoding and normalization. This can allow an authenticated user to access restricted resources if the default rule is more permissive than the specific locationRules intended to limit access. Consequently, sensitive data might be exposed when appropriate restrictions are circumvented.
