Posted by Timothy Legge on Sep 24 ======================================================================== CVE-2026-92288 CPAN Security Group ======================================================================== CVE ID: CVE-2026-92288 Distribution: Lemonldap-NG-Portal Versions: from 2.20.0 before 2.21.6 from 2.22.0 before 2.23.4 MetaCPAN: https://metacpan.org/dist/Lemonldap-NG-Portal...
CVE-2026-92288: Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Rely
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/933
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.

