---
id: CVE-2026-44476
title: Doorkeeper is an OAuth 2 provider for Ruby on Rails
summary: >-
  Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an
  attacker who knows only a dynamically registered client's client_id, which is
  public information, can authenticate as that client at the token endpoint and
  obtain …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-287
  - CWE-1390
vendor: doorkeeper-gem
product: doorkeeper-openid_connect
affected:
  - 'doorkeeper-openid_connect >= 1.9.0, < 1.10.0'
published: '2026-08-25'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:09:13.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44476'
references:
  - url: >-
      https://github.com/doorkeeper-gem/doorkeeper-openid_connect/commit/561af83dcf
    label: security-advisories@github.com
  - url: >-
      https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-m6vc-f87m-cc2h
    label: security-advisories@github.com
  - url: >-
      https://github.com/doorkeeper-gem/doorkeeper-openid_connect/security/advisories/GHSA-m6vc-f87m-cc2h
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-26T15:38:41.089218Z'
cvssSource: cna
ingestedAt: '2026-09-12T15:54:14.574Z'
epss: 0.00564
epssPercentile: 0.44668
---

## Overview

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
