CWE-1390

CWE-1390 · 4 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-1390, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-92289

    Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE s…

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-92288

    Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndP…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-93355

    LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without veri…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.1CVE-2026-94455public PoC

    An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on that list, so no authenti…

    AI risk analysis on Exploit-DB.ai →