OAuth Dynamic Client Registration Detected

info Web App Scanning Plugin ID 114918

Synopsis

OAuth Dynamic Client Registration Detected

Description

This is an informational plugin to inform the user that the scanner has detected a publicly accessible OAuth Dynamic Client Registration endpoint on the target application. OAuth Dynamic Client Registration allows clients to register dynamically with an authorization server and is very common in the context of Model Context Protocol (MCP) servers used for AI development.

Solution

Ensure that allowing OAuth client dynamic registration is expected on the target application.

See Also

https://datatracker.ietf.org/doc/html/rfc7591

https://medium.com/@abilashini/oauth-2-0-dynamic-client-registration-management-dcrm-protocol-b55f222f481b

Plugin Details

Severity: Info

ID: 114918

Type: remote

Published: 7/18/2025

Updated: 7/18/2025

Scan Template: api, basic, full, pci, scan