THREAT OPS › Threat News › CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
<p>Posted by Timothy Legge on Aug 16</p>========================================================================<br /> CVE-2026-19349 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-19349<br /> Distribution: Lemonldap-NG-Portal<br /> Versions: from 2.0.0 befo
Indicators of compromise
- CVE-2026-19349cve
Original source: https://seclists.org/oss-sec/2026/q3/505