SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82754

MEDIUM · CVSS 6.3 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ash_authentication_oauth2_server is vulnerable due to improper protection of OAuth endpoints, allowing state-changing operations to be accessed via unintended URL prefixes, specifically /.well-known. This misconfiguration can lead to bypassing security controls, potentially exposing sensitive actions like registration and token management to unauthorized access. Organizations using affected versions (0.1.0 to 0.3.1) should prioritize remediation to secure their OAuth implementations against this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82754
Severity
MEDIUM
CVSS
6.3
EPSS
0.39%

Original NVD Description

Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias. This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.