CVE-2026-70665 MEDIUM

CVE-2026-70665: Doorkeeper OpenID Connect: DCR endpoint persists unvalidated client-supplied scopes

Vendor Doorkeeper-Gem
Product doorkeeper-openid_connect
Weakness CWE-285
Published August 25, 2026
Last update August 27, 2026

CVSS base score

4.2/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

04Related CVE