oss-security·2d agoCVE-2026-92288: Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party#lemonldap#oauth2#token-introspectionCVE-2026-92288 3 sources
oss-security·12d agoCVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass#apache#cve-2026-87802#jwtCVE-2026-878021