HomeSecurityLemonLDAP NG: New vulnerability bypasses access rules

LemonLDAP NG: New vulnerability bypasses access rules

LemonLDAP NG is affected by the new vulnerability CVE-2026-95811, which can bypass access rules when a path is written in a different, but equivalent, format. The issue affects installations using the Handler component for Perl and requires immediate version control.

LemonLDAP NG path canonicalization

The CVE Alert describes a mismatch between the address checked by regular expressions and the path ultimately processed by the server. There is no published CVSS score or indication that the vulnerability is being actively exploited.

See also: GitLab: Critical path traversal vulnerability requires immediate update

How the vulnerability in LemonLDAP NG works

LemonLDAP NG uses locationRules to decide whether a URL should be allowed, denied, or requires a specific identity and group. In vulnerable versions, the Handler for Perl compares the rules to the REQUEST_URI, i.e. the original form of the request.

Later, the web server can decode and normalize the route before routing it. So, an address with encoded characters, dot segments, or double slashes can end up at the same protected resource, but not match the regular expression of the rule.

Bypassing does not automatically grant a guest full access. This mainly affects virtual machines where the default result is more permissive than the specific rules. In such a configuration, an already authenticated user can reach URLs that administrators had restricted with a rule.

LemonLDAP NG protected resources

The technical description of the entry notes that deny rules, identity or group conditions, as well as unprotect and skip. The actual result depends on the settings of each virtual machine and the permissions granted by the default rule.

Affected versions of LemonLDAP NG

The CVE-2026-95811 entry covers Handler for Perl from version 2.0.0 to before 2.16.10, from 2.17.0 to before 2.21.6, and from 2.22.0 to before 2.23.4. The patched versions are 2.16.10, 2.21.6, and 2.23.4, respectively.

The image is especially useful for administrators using long-term support branches. The project's release support policy shows that the 2.16.x and 2.21.x series remain important for organizations that cannot immediately move to the latest version.

There is also a difference between the project version and the distribution packages. The Debian Security Tracker lists the vulnerability as open for bookworm and trixie, while it shows it fixed in sid. Therefore, it is not enough to look for the version within the project environment; you need to check the package provided by the operating system.

See also: nvm version 0.40.8: Urgent update for path traversal

What administrators should check

The priority is to upgrade to a patched version of LemonLDAP NG, depending on the branch being used. After the change, teams should review access rules and confirm that sensitive routes are not based on an overly permissive default result.

It is best to test at the virtual machine level, not just the central configuration. You should test with URLs that contain encoded characters, dot segments, and double slashes to see if the policy is applied to the final, canonical path. Tests should be done in a controlled environment and the results should be recorded.

LemonLDAP NG upgrade and protection

At the same time, it's worth examining logs for unusual URL variations and successful accesses to resources that would normally require a stricter rule. CVE-2026-95811 does not in itself document data theft or remote code execution, but an incorrect default rule can broaden access further than intended.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Microsoft Entra ID: Vulnerability affects account security

Audits should also cover intermediate layers, such as reverse proxies, load balancers, and redirection rules. A policy that looks correct in the admin console may change over time as different infrastructure components decode or compress the address. Comparing the logs at each layer helps identify where the constraint is broken.

Upgrading, verifying rules, and searching for related requests should be treated as a single process. This way, organizations narrow the window of exposure and confirm that the LemonLDAP NG access policy actually matches the path seen by the protected server. For LemonLDAP NG, proper URL canonicalization is as important as installing the patch.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS