CVE-2026-12804Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried out remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue. The vendor confirms, that "it has been fixed some days ago and will be available in 2.23.1. CDC is quite never used, so the impact is very low."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-21: 2Technical Details · 2026-06-21: 206-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12804 A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the co… https://www.cve.org/CVERecord?id=CVE-2026-12804 ----- Traducción: CVE-2026-12804 Se … http://infoflow.cloud`

    Post summary

    A brief notice reports a vulnerability in lemonldap-ng versions up to 2.23.0, providing a link to the CVE record and limited technical details but no exploitation or patch information.

    0000029
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12804 A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the co… https://www.cve.org/CVERecord?id=CVE-2026-12804

    Post summary

    A CVE-2026-12804 was identified in lemonldap-ng up to 2.23.0 affecting an unknown function in CDC.pm; no PoC, exploitation, or mitigation details are provided.

    00000828
    57.7K followersView on X

Explore more