A vulnerability labeled as critical has been found in OW2 LemonLDAP::NG up to 2.16.8/2.21.4/2.23.2. This affects the function
extractFormInfo of the component OAuth2. Such manipulation of the argument state leads to improper authentication.
This vulnerability is traded as CVE-2026-19349. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.