Description
Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token.

resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated any return other than {:ok, _} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or "" as {:ok, value}. When the initial_access_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing_secret.

This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Published: 2026-09-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The server treats any return value from the configured secret provider that is not {:ok, _} or :error as a valid secret, wrapping nil, false, or an empty string into {:ok, value}. When the initial access token resolves to such an empty secret, POST /oauth/register compares the supplied bearer token to this resolved secret; because the secret is effectively empty, the comparison succeeds even when no token is supplied. Consequently, the gated Dynamic Client Registration endpoint becomes open to anyone, allowing unauthenticated registration of OAuth clients and potentially yielding client credentials for malicious applications.

Affected Systems

ash-project's ash_authentication_oauth2_server, versions 0.1.0 through 0.3.0 (inclusive).

Risk and Exploitability

The vulnerability has a CVSS score of 6.3, indicating moderate severity. No EPSS data is available. The vulnerability is not listed in CISA KEV. An attacker can remotely exploit it by sending an unauthenticated POST request to the /oauth/register endpoint to create a new client application.

Generated by OpenCVE AI on September 7, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ash_authentication_oauth2_server to version 0.3.1 or later where the bug is fixed.
  • If an immediate upgrade is not possible, disable the Dynamic Client Registration endpoint or require that the resolved initial access token must be non‑empty before accepting a request.
  • Configure the secret provider to never return nil, false, or an empty string, or add an explicit check in your deployment to reject empty secrets before the registration logic runs.

Generated by OpenCVE AI on September 7, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated any return other than {:ok, _} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or "" as {:ok, value}. When the initial_access_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing_secret. This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Title ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
First Time appeared Ash-project
Ash-project ash Authentication Oauth2 Server
Weaknesses CWE-287
CPEs cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Authentication Oauth2 Server
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Authentication Oauth2 Server
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-07T22:32:17.027Z

Reserved: 2026-08-31T01:00:10.817Z

Link: CVE-2026-82758

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T23:16:53.123

Modified: 2026-09-07T23:16:53.123

Link: CVE-2026-82758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T23:30:17Z

Weaknesses