OAuth Wikipedia
Where this cannot be avoided, authorization servers MUST provide other means for the resource server to distinguish between the two types of access tokens.¶ This attack potentially affects not only implementations using RFC9068, but also similar, bespoke solutions.¶ If the resource server cannot properly distinguish between access tokens obtained with involvement of the resource owner […]