CVE-2026-70665General

LOWCVSS 4.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-25); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-25: 2Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-26: 108-2508-26
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-252
General1Patch1
2026-08-261
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-70665 Privilege Escalation in Doorkeeper OpenID Connect Prior to 1.10.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-70665

    Post summary

    CVE-2026-70665 is a privilege escalation issue affecting Doorkeeper OpenID Connect versions prior to 1.10.4, with technical details linked via the provided URL.

    00000126
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-70665 Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Regist… https://www.cve.org/CVERecord?id=CVE-2026-70665 ----- Traducción: CVE-2026-70665 Doo… https://infoflow.cloud`

    Post summary

    The tweet merely notes the existence of CVE-2026-70665 and links to the CVE record, offering no further technical or exploitation details.

    0000045
    102 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-70665 Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Regist… https://www.cve.org/CVERecord?id=CVE-2026-70665

    Post summary

    CVE‑2026‑70665 impacts Doorkeeper OpenID Connect; the vulnerability existed in versions prior to 1.10.4 and was addressed in that release. No PoC, exploit, or active exploitation details are provided.

    000001.3K
    58.0K followersView on X

Explore more