CVE-2026-92289: Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret
CVE-2026-92289 lets LemonLDAP::NG public OAuth clients bypass PKCE because client secrets are not verified.
CVE-2026-92289 affects Lemonldap::NG::Portal for Perl from 2.23.0 before 2.23.4. In "PKCE or secret" mode, checkEndPointAuthenticationCredentials does not verify the client secret of a public relying party, allowing a PKCE bypass. The report was posted to oss-security by Timothy Legge. No exploitation in the wild is described.