PT-2026-46299 · Doorkeeper Gem+4 · Doorkeeper::Openidconnect+1

·

CVE-2026-44476

·

Published

2026-06-04

·

Updated

2026-08-26

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Doorkeeper versions prior to 1.10.0
Description An issue exists in the Dynamic Client Registration feature where applications are created with the confidential variable hard-coded to false. Although the registration response provides a client secret and claims support for client secret basic and client secret post authentication methods, the secret is never verified because the system treats blank or missing secrets as valid for non-confidential clients. Consequently, an attacker possessing only the client id can authenticate at the token endpoint and obtain an access token without a secret. This affects only projects that have explicitly enabled Dynamic Client Registration, as it is disabled by default. The flaw is located in the DynamicClientRegistrationController#register action and the Application.by uid and secret() function.
Recommendations Update to version 1.10.0. As a temporary workaround, update existing applications created via Dynamic Client Registration to set confidential: true.

Exploit

Fix

Improper Authentication

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44476
GHSA-M6VC-F87M-CC2H

Affected Products

Doorkeeper::Openidconnect
Ruby-Doorkeeper-Openid-Connect