CVE-2026-108718
Rill 0.77.0 through 0.90.5 OAuth Missing Authorization via Dynamic Client Registration
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers can register a client with the long_lived_access_token scope and lure a user to an authorization link, obtaining a non-expiring API token with the user's full permissions.
| CWE | CWE-862 |
| Vendor | rill data |
| Product | rill |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for rill data rill
Be the first to know when new high vulnerabilities affecting rill data rill are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Rill Data / rill
0.77.0 โค 0.90.5
References
hackmd.io: https://hackmd.io/@haind03/rill-oauth-open-registration-long-lived-token github.com: https://github.com/rilldata/rill/blob/b9ea8c6f215e56c4c0848771e70b3ec38346eacc/admin/server/auth/handlers.go#L650-L697 github.com: https://github.com/rilldata/rill/blob/b9ea8c6f215e56c4c0848771e70b3ec38346eacc/admin/server/auth/mcp_oauth.go#L77-L153 github.com: https://github.com/rilldata/rill/blob/b9ea8c6f215e56c4c0848771e70b3ec38346eacc/admin/server/auth/pkce.go#L173-L214 github.com: https://github.com/rilldata/rill vulncheck.com: https://www.vulncheck.com/advisories/rill-0.77.0-through-0.90.5-oauth-missing-authorization-via-dynamic-client-registration
Credits
HaiND from the Post and Telecommunication Institute of Technology