Improper Authentication in Ash Project's OAuth2 Server Affects Dynamic Client Registration
CVE-2026-82758
Key Information:
- Vendor
Ash-project
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-82758?
The Ash Project's ash_authentication_oauth2_server contains an improper authentication vulnerability that allows unauthenticated attackers to register OAuth clients without appropriate checks. This flaw arises when the dynamic client registration process incorrectly validates initial access tokens. Specifically, when the resolved secret returns a nil, false, or an empty string, the system mistakenly allows client registration, exposing the application to unauthorized credential abuse. Versions from 0.1.0 to prior to 0.3.1 are affected, necessitating immediate action to mitigate this issue through the latest patches.
Affected Version(s)
ash_authentication_oauth2_server 0.1.0 < 0.3.1
ash_authentication_oauth2_server 855b578037c5ded18e8a6e60f42e56bde4905fae < 30a87101871775d27d79f9ad6f29eafa4779e118
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
