CVE-2026-44476: CWE-287: Improper Authentication in doorkeeper-gem doorkeeper-openid_connect
Description
CVE-2026-44476 is an improper authentication vulnerability in the doorkeeper-openid_connect gem version 1.9.0. It allows an attacker who knows a dynamically registered client's client_id to obtain an access token without providing the client_secret. This occurs because dynamically registered clients are incorrectly marked as non-confidential, causing the client_secret verification to be skipped. The issue affects only projects that have enabled Dynamic Client Registration, which is disabled by default. The vulnerability is fixed in version 1.10.0.
CVSS v4.0
Score 6.3medium
Affected software
doorkeeper-gem
doorkeeper-openid_connect
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In doorkeeper-openid_connect version 1.9.0, the Dynamic Client Registration feature creates applications with confidential: false hard-coded, despite returning a client_secret and advertising client_secret authentication methods. Since Doorkeeper treats a blank or missing secret as valid for non-confidential clients, the client_secret is never verified at the token endpoint. An attacker knowing only the public client_id can authenticate as that client and obtain an access token without the secret. This affects only projects with Dynamic Client Registration enabled. The vulnerability is resolved in version 1.10.0.
Potential Impact
An attacker can impersonate a dynamically registered client by using only its public client_id to obtain access tokens without needing the client_secret. This breaks the intended authentication mechanism and could lead to unauthorized access to protected resources. The impact is limited to environments where Dynamic Client Registration is explicitly enabled.
Mitigation Recommendations
Upgrade to doorkeeper-openid_connect version 1.10.0 or later, where this issue is fixed. If upgrading is not immediately possible, disable Dynamic Client Registration as it is disabled by default and only affected when explicitly enabled.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-06T17:18:51.782Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8e1ce6acd9273b49d02183
Added to database: 08/25/2026, 22:53:26 UTC
Last enriched: 09/10/2026, 12:23:38 UTC
Last updated: 10/09/2026, 06:48:17 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.