EEF-CVE-2026-82758

    Dashboard / Vulnerabilities / EEF-CVE-2026-82758

    EEF-CVE-2026-82758

    Published: 7 Sept 2026Last Modified: 7 Sept 2026

    Summary: ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint

    Details: ## Summary Improper Authentication vulnerability in ash-project ash\_authentication\_oauth2\_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve\_secret/3 in AshAuthentication.Oauth2Server (reached through \_\_resolve\_secret\_\_!) treated any return other than {:ok, \_} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or "" as {:ok, value}. When the initial\_access\_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing\_secret. This issue affects ash\_authentication\_oauth2\_server: from 0.1.0 before 0.3.1. ## Configuration Reachable only when the server configures an initial\_access\_token (so Dynamic Client Registration is meant to require one) and the configured secret provider returns an empty value (nil, false, or "") or an {:error, \_} for it, rather than a non-empty binary.

    Affected packages

    Package

    Name: ash_authentication_oauth2_server

    Purl: pkg:hex/ash_authentication_oauth2_server

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.1.0
    Fixed -0.3.1

    Affected versions

    0.1.0
    0.1.1
    0.1.2
    0.1.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High