<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:rilldata:rill:0.77.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arilldatarill0.77.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arilldatarill0.77.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Missing Authorization Vulnerability in Rill Admin OAuth Server</title><link>https://feed.craftedsignal.io/briefs/2026-10-rill-oauth-vuln/</link><pubDate>Sun, 11 Oct 2026 14:01:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-rill-oauth-vuln/</guid><description>Rill versions 0.77.0 through 0.90.5 contain a missing authorization vulnerability that allows attackers to obtain non-expiring API tokens with elevated permissions via unauthorized OAuth code issuance.</description><content:encoded><![CDATA[<p>Rill versions 0.77.0 through 0.90.5 are affected by a missing authorization vulnerability within the admin OAuth server component. This flaw permits the dynamic registration of OAuth clients that can request elevated scopes, such as long_lived_access_token, without obtaining explicit user consent. An attacker can exploit this by registering a malicious client and tricking a legitimate user into visiting a crafted authorization link. Upon the user's interaction, the system issues a non-expiring API token directly to the attacker-controlled client, granting the attacker the user's full permissions. This vulnerability enables persistent access and potential exfiltration of sensitive analytics or metadata managed within the Rill environment. Organizations utilizing Rill versions 0.77.0 to 0.90.5 are at risk of complete account takeover if users interact with attacker-supplied authorization links.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized generation of non-expiring API tokens, granting attackers persistent access to user data and Rill platform resources. This can lead to significant data exfiltration, unauthorized modification of analytics configurations, and loss of environment control. The severity is highlighted by a CVSS v3.1 base score of 8.1, reflecting high potential for unauthorized access and privilege escalation.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering and security teams:</p>
<ul>
<li>Upgrade all instances of Rill to a version beyond 0.90.5 immediately to patch CVE-2026-108718.</li>
<li>Audit OAuth client registrations in Rill administrative logs for any unexpected or dynamically registered client IDs initiated during the period of exposure.</li>
<li>Review logs for OAuth authorization requests where the requested scope includes long_lived_access_token and the client was not pre-approved or vetted by administrative policy.</li>
<li>Implement stricter access control policies for dynamic client registration to prevent unauthorized third-party integrations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>