High-Risk OAuth Vulnerabilities Disclosed in Rill and AmoyLab Products
Article Content
- •CVE-2026-108718 allows unauthorized client registration in Rill OAuth.
- •CVE-2026-108865 enables authentication bypass in AmoyLab Unla OAuth.
- •Both vulnerabilities are classified as high severity with no patches available.
Two vulnerabilities have been disclosed affecting Rill and AmoyLab OAuth implementations. CVE-2026-108718 in Rill versions 0.77.0 to 0.90.5 allows unauthorized client registration due to missing authentication on the dynamic client registration endpoint. CVE-2026-108865 in AmoyLab Unla version 0.10.0 enables an authentication bypass via the /authorize endpoint, allowing anonymous users to obtain authorization codes. Both vulnerabilities have been reported by independent researchers and are pending coordinated disclosure. No patches have been released yet, and both vulnerabilities are classified as high severity with CVSS scores of 8.6 and 8.8 respectively. The affected systems include the Rill admin server and AmoyLab's self-hosted MCP gateway, both of which are for managing OAuth2 authorization.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AmoyLab Unla and CVE-2026-108718 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is there a patch available?
What should organizations do?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…