Authentication Bypass in AmoyLab Unla Affects OAuth2 Security
CVE-2026-108865

8.8HIGH

Key Information:

Vendor

Amoylab

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108865?

AmoyLab's Unla product, up to version 0.10.0, contains a serious flaw that enables unauthenticated attackers to exploit the OAuth2 server. The vulnerability arises from the server's failure to authenticate resource owners, permitting malicious users to register clients and request authorization codes through the /authorize endpoint. Once this code is obtained, attackers can exchange it at /token, gaining unauthorized access to OAuth2-protected MCP prefixes, upstream APIs, and additional credentials. This presents a significant risk for securing sensitive resources and data.

Affected Version(s)

Unla 0 <= 0.10.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.