Improper Authentication in Ash Project's OAuth2 Server Affects Dynamic Client Registration
CVE-2026-82758

6.3MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-82758?

The Ash Project's ash_authentication_oauth2_server contains an improper authentication vulnerability that allows unauthenticated attackers to register OAuth clients without appropriate checks. This flaw arises when the dynamic client registration process incorrectly validates initial access tokens. Specifically, when the resolved secret returns a nil, false, or an empty string, the system mistakenly allows client registration, exposing the application to unauthorized credential abuse. Versions from 0.1.0 to prior to 0.3.1 are affected, necessitating immediate action to mitigate this issue through the latest patches.

Affected Version(s)

ash_authentication_oauth2_server 0.1.0 < 0.3.1

ash_authentication_oauth2_server 855b578037c5ded18e8a6e60f42e56bde4905fae < 30a87101871775d27d79f9ad6f29eafa4779e118

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.