THREATOPS
THREAT OPSThreat News › CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends

CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends

medoss_secPublished 2026-08-16

<p>Posted by Timothy Legge on Aug 16</p>========================================================================<br /> CVE-2026-19349 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-19349<br /> Distribution: Lemonldap-NG-Portal<br /> Versions: from 2.0.0 befo

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/505