CRITICAL
Lemonldap::NG
CVE published 2026-08-16
CVE-2026-19349
The Lemonldap::NG::Portal, specifically versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, and from 2.22.0 before 2.23.3, is vulnerable to an authentication bypass attack via an OAuth2 state parameter stored as an SSO session in GitHub and LinkedIn backends. This vulnerability arises from the mishandling of the state session in the extractFormInfo() function, allowing any visitor to replay the [truncated]