CVE-2026-12804
MEDIUMlemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect
Title source: cnaDescription
A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried out remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue. The vendor confirms, that "it has been fixed some days ago and will be available in 2.23.1. CDC is quite never used, so the impact is very low."
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-372598 | lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect
https://vuldb.com/vuln/372598
Signature, Permissions Required signature
permissions-required
VDB-372598 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/372598/cti
Third Party Advisory third-party-advisory
CVE-2026-12804 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-12804
Third Party Advisory third-party-advisory
Submit #836105 | lemonldap lemonldap-ng ca7af863ac5f60d127ba01e8661c0365be374d4b Open Redirect
https://vuldb.com/submit/836105
Scores
CVSS v3
4.3
EPSS
0.0045
EPSS Percentile
36.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (24)
None/lemonldap-ng
2.0
None/lemonldap-ng
2.1
None/lemonldap-ng
2.10
None/lemonldap-ng
2.11
None/lemonldap-ng
2.12
None/lemonldap-ng
2.13
None/lemonldap-ng
2.14
None/lemonldap-ng
2.15
None/lemonldap-ng
2.16
None/lemonldap-ng
2.17
... and 14 more
Published
Jun 21, 2026
Tracked Since
Jun 22, 2026