Authentication Bypass in AmoyLab Unla
AmoyLab Unla versions 0.10.0 and earlier are vulnerable to an authentication bypass in the OAuth2 implementation that permits unauthenticated attackers to obtain valid access tokens and interact with restricted APIs.
CVE search metadata
CVE search record: CVE-2026-108865. Severity: high. CVSS: 8.2. KEV: no. Product: Unla (<= 0.10.0). Brief: Authentication Bypass in AmoyLab Unla. Brief link: https://feed.craftedsignal.io/briefs/2026-10-amoylab-unla-auth-bypass/
AmoyLab Unla, an OAuth2 server implementation, contains a critical authentication bypass vulnerability (CVE-2026-108865) affecting versions 0.10.0 and earlier. The security flaw stems from the server's failure to properly authenticate the resource owner during the OAuth2 authorization flow. This defect allows unauthenticated attackers to register their own client, initiate an authorization request, and successfully exchange it for valid access tokens via the /token endpoint.
Successful exploitation enables an attacker to gain unauthorized access to OAuth2-protected Model Context Protocol (MCP) prefixes and proxied upstream APIs. Furthermore, attackers can gain access to credentials injected into these proxied services. Given the nature of the vulnerability as an authentication bypass, it represents a significant risk for organizations relying on Unla for identity mediation or API protection, as it effectively nullifies the expected security boundary for downstream services.
Impact
Successful exploitation of this vulnerability allows unauthorized actors to bypass authentication controls and interact with protected internal resources. Impacted organizations face potential data exfiltration from proxied upstream APIs, unauthorized use of injected credentials, and total compromise of restricted MCP prefixes. The CVSS 3.1 score of 8.2 reflects the high potential for impact on confidentiality and integrity within integrated service environments.
Recommendation
- Prioritize the identification of all instances of AmoyLab Unla within the environment to determine exposure.
- Monitor access logs for suspicious OAuth2 client registration activity followed by rapid requests to the /authorize and /token endpoints from unidentified or unauthorized sources.
- Update all instances of AmoyLab Unla to a patched version beyond 0.10.0 once available.
- Implement additional API gateway-level authentication checks for services proxied behind Unla as a temporary compensatory control until patching can be completed.
Immediate actions
Inventory all servers running AmoyLab Unla and prepare for emergency patching
Mitigations
Upgrade AmoyLab Unla to the latest version beyond 0.10.0
CVE-2026-108865