Description
Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token.

resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated any return other than {:ok, _} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or "" as {:ok, value}. When the initial_access_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing_secret.

This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Published: 2026-09-07
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: unauthenticated OAuth client registration
Action: Patch Now
AI Analysis

Impact

The server treats any return value from the configured secret provider that is not {:ok, _} or :error as a valid secret, wrapping nil, false, or an empty string into {:ok, value}. When the initial access token resolves to such an empty secret, POST /oauth/register compares the supplied bearer token to this resolved secret; because the secret is effectively empty, the comparison succeeds even when no token is supplied. Consequently, the gated Dynamic Client Registration endpoint becomes open to anyone, allowing unauthenticated registration of OAuth clients and potentially yielding client credentials for malicious applications.

Affected Systems

ash-project's ash_authentication_oauth2_server, versions 0.1.0 through 0.3.0 (inclusive).

Risk and Exploitability

The vulnerability has a CVSS score of 6.3, indicating moderate severity. No EPSS data is available. The vulnerability is not listed in CISA KEV. An attacker can remotely exploit it by sending an unauthenticated POST request to the /oauth/register endpoint to create a new client application.

Generated by OpenCVE AI on September 7, 2026 at 23:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ash_authentication_oauth2_server to version 0.3.1 or later where the bug is fixed.
  • If an immediate upgrade is not possible, disable the Dynamic Client Registration endpoint or require that the resolved initial access token must be non‑empty before accepting a request.
  • Configure the secret provider to never return nil, false, or an empty string, or add an explicit check in your deployment to reject empty secrets before the registration logic runs.

Generated by OpenCVE AI on September 7, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated any return other than {:ok, _} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or "" as {:ok, value}. When the initial_access_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing_secret. This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Title ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
First Time appeared Ash-project
Ash-project ash Authentication Oauth2 Server
Weaknesses CWE-287
CPEs cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Authentication Oauth2 Server
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Authentication Oauth2 Server
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-08T14:41:06.227Z

Reserved: 2026-08-31T01:00:10.817Z

Link: CVE-2026-82758

cve-icon Vulnrichment

Updated: 2026-09-08T14:41:01.131Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T23:16:53.123

Modified: 2026-09-08T15:18:50.977

Link: CVE-2026-82758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T02:00:19Z

Weaknesses