Authentication Bypass in AmoyLab Unla Affects OAuth2 Security
CVE-2026-108865
8.8HIGH
What is CVE-2026-108865?
AmoyLab's Unla product, up to version 0.10.0, contains a serious flaw that enables unauthenticated attackers to exploit the OAuth2 server. The vulnerability arises from the server's failure to authenticate resource owners, permitting malicious users to register clients and request authorization codes through the /authorize endpoint. Once this code is obtained, attackers can exchange it at /token, gaining unauthorized access to OAuth2-protected MCP prefixes, upstream APIs, and additional credentials. This presents a significant risk for securing sensitive resources and data.
Affected Version(s)
Unla 0 <= 0.10.0
