SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82758

MEDIUM · CVSS 6.3 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ash_authentication_oauth2_server is vulnerable due to improper authentication that allows unauthenticated attackers to register OAuth clients, bypassing security measures intended to restrict access. The impact includes unauthorized client registrations, potentially leading to data breaches or unauthorized access to sensitive resources. Organizations using versions 0.1.0 to 0.3.0 of this library should prioritize patching to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82758
Severity
MEDIUM
CVSS
6.3
EPSS
0.38%

Original NVD Description

Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated any return other than {:ok, _} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or "" as {:ok, value}. When the initial_access_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing_secret. This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.