Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Doorkeeper-gem
Doorkeeper-gem doorkeeper-openid Connect |
|
| Vendors & Products |
Doorkeeper-gem
Doorkeeper-gem doorkeeper-openid Connect |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4. | |
| Title | Doorkeeper OpenID Connect: DCR endpoint persists unvalidated client-supplied scopes | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-27T14:34:50.455Z
Reserved: 2026-08-04T21:48:08.613Z
Link: CVE-2026-70665
Updated: 2026-08-27T13:52:59.700Z
Status : Received
Published: 2026-08-25T23:17:58.933
Modified: 2026-08-27T17:19:43.340
Link: CVE-2026-70665
No data.
OpenCVE Enrichment
Updated: 2026-08-28T20:34:21Z