Description
Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix.

oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias.

This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Published: 2026-09-07
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of OAuth endpoint controls via aliases
Action: Patch
AI Analysis

Impact

The flaw causes the OAuth2 server to expose the state‑changing endpoints /register, /token, and /revoke under both the intended /oauth prefix and an unintended /.well‑known prefix. Because Phoenix forwards without applying the prefix, the same route handlers are available from /.well‑known. This bypasses any path‑scoped controls such as WAF rules, rate limits or authentication exemptions that were defined only for the /oauth paths. An attacker who can reach the application can therefore issue token‑request or revocation calls without triggering the intended safeguards, leading to unauthorized token issuance or forced token revocation. The issue is a CWE‑424 vulnerability.

Affected Systems

Any deployment of ash‑project’s ash_authentication_oauth2_server from version 0.1.0 up to and including 0.3.0 is vulnerable. This includes applications that embed the library and rely on the default /oauth mounting without adding custom protections.

Risk and Exploitability

The CVSS score of 6.3 classifies the issue as moderately severe. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is straightforward: a network actor can send HTTP POST requests to the exposed /.well‑known endpoints with no special privileges. Because WAF rules, rate limits, or authentication checks written for /oauth do not apply to /.well‑known, the attacker can perform OAuth flows – such as registering clients, obtaining tokens, or revoking tokens – without encountering the intended protections, potentially gaining unauthorized access or disrupting legitimate sessions.

Generated by OpenCVE AI on September 7, 2026 at 23:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ash_authentication_oauth2_server to version 0.3.1 or later, which removes the aliasing of /oauth routes under /.well‑known.
  • Reconfigure the application’s routing so that OAuth endpoints are mounted exclusively under /oauth and the /.well‑known prefix is no longer used, ensuring path‑scoped controls remain effective.
  • If upgrading is not immediately possible, implement explicit authentication checks or rate limiting on /.well‑known routes to mirror the protections applied to the original /oauth endpoints, thereby preventing abuse of the inverted paths.

Generated by OpenCVE AI on September 7, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias. This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Title ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
First Time appeared Ash-project
Ash-project ash Authentication Oauth2 Server
Weaknesses CWE-424
CPEs cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Authentication Oauth2 Server
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Authentication Oauth2 Server
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-08T14:41:45.077Z

Reserved: 2026-08-31T01:00:10.817Z

Link: CVE-2026-82754

cve-icon Vulnrichment

Updated: 2026-09-08T14:41:40.566Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T23:16:52.403

Modified: 2026-09-08T15:18:50.320

Link: CVE-2026-82754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T01:00:11Z

Weaknesses
  • CWE-424

    Improper Protection of Alternate Path