CVE-2026-108865

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,2
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: low
Availability: none

Description

AI Translation Available

AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resource owner. Attackers can register a client, request a code from /authorize, and exchange it at /token to access OAuth2-protected MCP prefixes, proxied upstream APIs and injected credentials.

287

Improper Authentication

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Access Control
Potential Impacts:
Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies: Not Technology-Specific, Web Based, ICS/OT
View CWE Details
https://github.com/AmoyLab/Unla
https://github.com/AmoyLab/Unla/blob/v0.10.0/internal/auth/oauth.go#L86-L147
https://github.com/AmoyLab/Unla/blob/v0.10.0/internal/core/server.go#L229-L261
https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/amoylab-unla-oauth-self-issued-token-…
https://www.vulncheck.com/advisories/amoylab-unla-through-0.10.0-oauth2-authent…