CVE-2026-108865
AmoyLab Unla through 0.10.0 OAuth2 Authentication Bypass via /authorize
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resource owner. Attackers can register a client, request a code from /authorize, and exchange it at /token to access OAuth2-protected MCP prefixes, proxied upstream APIs and injected credentials.
| CWE | CWE-287 |
| Vendor | amoylab |
| Product | unla |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for amoylab unla
Be the first to know when new high vulnerabilities affecting amoylab unla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
AmoyLab / Unla
0 โค 0.10.0
References
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/amoylab-unla-oauth-self-issued-token-authz github.com: https://github.com/AmoyLab/Unla/blob/v0.10.0/internal/auth/oauth.go#L86-L147 github.com: https://github.com/AmoyLab/Unla/blob/v0.10.0/internal/core/server.go#L229-L261 github.com: https://github.com/AmoyLab/Unla vulncheck.com: https://www.vulncheck.com/advisories/amoylab-unla-through-0.10.0-oauth2-authentication-bypass-via-authorize
Credits
hieuPenguinnn