Improper Authorization in Doorkeeper - #VU140708
Published: August 1, 2026
Doorkeeper
Detailed vulnerability description
The vulnerability allows a remote attacker to revoke tokens without correct authorization.
The vulnerability exists due to improper authorization in the OAuth token revocation endpoint when handling token revocation requests for public (non-confidential) clients. A remote attacker can send a crafted token revocation request to revoke tokens without correct authorization.
Only deployments using public (non-confidential) clients in the OAuth token revocation flow are vulnerable.