Skip to content
Threat Feed
high advisory

Authentication Bypass in AmoyLab Unla

AmoyLab Unla versions 0.10.0 and earlier are vulnerable to an authentication bypass in the OAuth2 implementation that permits unauthenticated attackers to obtain valid access tokens and interact with restricted APIs.

CVE search metadata

CVE search record: CVE-2026-108865. Severity: high. CVSS: 8.2. KEV: no. Product: Unla (<= 0.10.0). Brief: Authentication Bypass in AmoyLab Unla. Brief link: https://feed.craftedsignal.io/briefs/2026-10-amoylab-unla-auth-bypass/

AmoyLab Unla, an OAuth2 server implementation, contains a critical authentication bypass vulnerability (CVE-2026-108865) affecting versions 0.10.0 and earlier. The security flaw stems from the server's failure to properly authenticate the resource owner during the OAuth2 authorization flow. This defect allows unauthenticated attackers to register their own client, initiate an authorization request, and successfully exchange it for valid access tokens via the /token endpoint.

Successful exploitation enables an attacker to gain unauthorized access to OAuth2-protected Model Context Protocol (MCP) prefixes and proxied upstream APIs. Furthermore, attackers can gain access to credentials injected into these proxied services. Given the nature of the vulnerability as an authentication bypass, it represents a significant risk for organizations relying on Unla for identity mediation or API protection, as it effectively nullifies the expected security boundary for downstream services.

Impact

Successful exploitation of this vulnerability allows unauthorized actors to bypass authentication controls and interact with protected internal resources. Impacted organizations face potential data exfiltration from proxied upstream APIs, unauthorized use of injected credentials, and total compromise of restricted MCP prefixes. The CVSS 3.1 score of 8.2 reflects the high potential for impact on confidentiality and integrity within integrated service environments.

Recommendation

  • Prioritize the identification of all instances of AmoyLab Unla within the environment to determine exposure.
  • Monitor access logs for suspicious OAuth2 client registration activity followed by rapid requests to the /authorize and /token endpoints from unidentified or unauthorized sources.
  • Update all instances of AmoyLab Unla to a patched version beyond 0.10.0 once available.
  • Implement additional API gateway-level authentication checks for services proxied behind Unla as a temporary compensatory control until patching can be completed.

Immediate actions

Inventory all servers running AmoyLab Unla and prepare for emergency patching

IT Operations 24h

Mitigations

Upgrade AmoyLab Unla to the latest version beyond 0.10.0

immediate IT Operations

CVE-2026-108865