Skip to main content
EPSS 0.6%top 55%

CVE-2026-44476: CWE-287: Improper Authentication in doorkeeper-gem doorkeeper-openid_connect

0
Medium
VulnerabilityCVE-2026-44476cvecve-2026-44476cwe-287cwe-1390
Published: 08/25/2026 (08/25/2026, 22:47:54 UTC)
Source: CVE Database V5
Vendor/Project: doorkeeper-gem
Product: doorkeeper-openid_connect

Description

CVE-2026-44476 is an improper authentication vulnerability in the doorkeeper-openid_connect gem version 1.9.0. It allows an attacker who knows a dynamically registered client's client_id to obtain an access token without providing the client_secret. This occurs because dynamically registered clients are incorrectly marked as non-confidential, causing the client_secret verification to be skipped. The issue affects only projects that have enabled Dynamic Client Registration, which is disabled by default. The vulnerability is fixed in version 1.10.0.

CVSS v4.0

Score 6.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected software

doorkeeper-gem

doorkeeper-openid_connect

Affected versions
>=1.9.0 <1.10.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 12:23:38 UTC

Technical Analysis

In doorkeeper-openid_connect version 1.9.0, the Dynamic Client Registration feature creates applications with confidential: false hard-coded, despite returning a client_secret and advertising client_secret authentication methods. Since Doorkeeper treats a blank or missing secret as valid for non-confidential clients, the client_secret is never verified at the token endpoint. An attacker knowing only the public client_id can authenticate as that client and obtain an access token without the secret. This affects only projects with Dynamic Client Registration enabled. The vulnerability is resolved in version 1.10.0.

Potential Impact

An attacker can impersonate a dynamically registered client by using only its public client_id to obtain access tokens without needing the client_secret. This breaks the intended authentication mechanism and could lead to unauthorized access to protected resources. The impact is limited to environments where Dynamic Client Registration is explicitly enabled.

Mitigation Recommendations

Upgrade to doorkeeper-openid_connect version 1.10.0 or later, where this issue is fixed. If upgrading is not immediately possible, disable Dynamic Client Registration as it is disabled by default and only affected when explicitly enabled.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-06T17:18:51.782Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a8e1ce6acd9273b49d02183

Added to database: 08/25/2026, 22:53:26 UTC

Last enriched: 09/10/2026, 12:23:38 UTC

Last updated: 10/09/2026, 06:48:17 UTC

Views: 82

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses