Posted by Timothy Legge on Sep 24 ======================================================================== CVE-2026-92289 CPAN Security Group ======================================================================== CVE ID: CVE-2026-92289 Distribution: Lemonldap-NG-Portal Versions: from 2.23.0 before 2.23.4 MetaCPAN: https://metacpan.org/dist/Lemonldap-NG-Portal VCS Repo:...
CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/934
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.
