CVE-2026-108865
Received Received - Intake

Authentication Bypass in AmoyLab Unla OAuth2 Server

Vulnerability report for CVE-2026-108865, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resource owner. Attackers can register a client, request a code from /authorize, and exchange it at /token to access OAuth2-protected MCP prefixes, proxied upstream APIs and injected credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
AmoyLab Unla 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AmoyLab Unla through version 0.10.0 has an authentication bypass flaw. Unauthenticated attackers can exploit this by registering a client, requesting a code from the /authorize endpoint, and exchanging it at /token to obtain valid access tokens. This allows access to OAuth2-protected MCP prefixes and upstream APIs.

Detection Guidance

Check for unauthenticated access to /authorize and /token endpoints in AmoyLab Unla. Look for suspicious client registrations or token requests without proper authentication. Monitor logs for unusual MCP prefix or API access patterns.

Impact Analysis

Attackers could gain unauthorized access to sensitive data or systems protected by OAuth2 in AmoyLab Unla. This may lead to data breaches, unauthorized actions, or further exploitation of connected services.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations using this software may face compliance violations and legal penalties.

Mitigation Strategies

Upgrade AmoyLab Unla to the latest version beyond 0.10.0. Restrict access to /authorize and /token endpoints. Implement strict client registration validation. Disable OAuth2 if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108865. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart