Improper Protection of Alternate Path Vulnerability in Ash-Project OAuth2 Server
CVE-2026-82754

6.3MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-82754?

The Ash-Project OAuth2 Server experiences an improper protection vulnerability, which allows state-changing OAuth endpoints to be reachable through unintended URL prefixes. This flaw arises because the same ProtocolRouter is forwarded at both the /oauth prefix and the /.well-known prefix. As a result, critical functionalities such as registering, token generation, and revocation become accessible at the unintended URLs: /.well-known/register, /.well-known/token, and /.well-known/revoke. Existing edge controls such as WAF rules and rate limits that are usually applied to the /oauth paths may not protect these endpoints, leading to potential unauthorized access.

Affected Version(s)

ash_authentication_oauth2_server 0.1.0 < 0.3.1

ash_authentication_oauth2_server 855b578037c5ded18e8a6e60f42e56bde4905fae

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.