CVE-2026-19349Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state session with the positional call `getApacheSession( undef, 1, 0, 'GitHubState' )`. getApacheSession() takes a session id followed by a named argument hash, so the trailing arguments become that hash, `kind` defaults to SSO, and the state is written to the global session storage as a regular SSO session. Its identifier is handed to the unauthenticated visitor as the state parameter of the redirection URL. Any visitor who reaches the GitHub or LinkedIn endpoint can replay that identifier as a session cookie and obtain a valid SSO session without authenticating. The session holds neither _user nor authenticationLevel, which the shipped bootstrap configuration accepts because it grants virtual hosts a "default => accept" access rule; deployments whose rules test the user or require an authentication level are less exposed. Only configurations with the GitHub or LinkedIn authentication module enabled are affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305CWE-628

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-16); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-16: 2Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-16: 2Technical Details · 2026-08-18: 108-1608-18
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-162
Disclosure2
2026-08-181
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-19349 Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state… https://www.cve.org/CVERecord?id=CVE-2026-19349

    Post summary

    The text announces CVE-2026-19349, detailing affected Lemonldap::NG::Portal versions and describing an OAuth2 state-based authentication bypass, linking to the official CVE record.

    000011.3K
    58.0K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🔐 CVE-2026-19349: Critical 9.8 auth bypass in LemonLDAP::NG::Portal. An OAuth2 state param stored as an SSO session lets attackers skip authentication entirely. Patch to 2.16.9, 2.21.5 or 2.23.3. #cybersecurity #ciso #sso #mssp https://secalerts.co/vulnerability/CVE-2026-19349?utm_campaign=x https://t.co/15l3MtqDaW

    Post summary

    The tweet reports a critical authentication bypass (CVE-2026-19349) in LemonLDAP::NG::Portal, outlines the flaw’s mechanism, and lists specific patch versions for remediation.

    00000152
    879 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19349 Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state… https://www.cve.org/CVERecord?id=CVE-2026-19349 ----- Traducción: CVE-2026-19349 Lem… https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-19349, describing an authentication bypass vulnerability in various Lemonldap::NG::Portal releases. No proof‑of‑concept, exploit code, active exploitation, or patch details are included.

    0000025
    99 followersView on X

Explore more