oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias.
This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias. This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1. | |
| Title | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls | |
| First Time appeared |
Ash-project
Ash-project ash Authentication Oauth2 Server |
|
| Weaknesses | CWE-424 | |
| CPEs | cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash Authentication Oauth2 Server |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-09-08T14:41:45.077Z
Reserved: 2026-08-31T01:00:10.817Z
Link: CVE-2026-82754
Updated: 2026-09-08T14:41:40.566Z
Status : Deferred
Published: 2026-09-07T23:16:52.403
Modified: 2026-09-08T15:18:50.320
Link: CVE-2026-82754
No data.
OpenCVE Enrichment
Updated: 2026-09-08T01:00:11Z