<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Unla (&lt;= 0.10.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/unla--0.10.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 16:03:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/unla--0.10.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in AmoyLab Unla</title><link>https://feed.craftedsignal.io/briefs/2026-10-amoylab-unla-auth-bypass/</link><pubDate>Sun, 11 Oct 2026 16:03:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-amoylab-unla-auth-bypass/</guid><description>AmoyLab Unla versions 0.10.0 and earlier are vulnerable to an authentication bypass in the OAuth2 implementation that permits unauthenticated attackers to obtain valid access tokens and interact with restricted APIs.</description><content:encoded><![CDATA[<p>AmoyLab Unla, an OAuth2 server implementation, contains a critical authentication bypass vulnerability (CVE-2026-108865) affecting versions 0.10.0 and earlier. The security flaw stems from the server's failure to properly authenticate the resource owner during the OAuth2 authorization flow. This defect allows unauthenticated attackers to register their own client, initiate an authorization request, and successfully exchange it for valid access tokens via the /token endpoint.</p>
<p>Successful exploitation enables an attacker to gain unauthorized access to OAuth2-protected Model Context Protocol (MCP) prefixes and proxied upstream APIs. Furthermore, attackers can gain access to credentials injected into these proxied services. Given the nature of the vulnerability as an authentication bypass, it represents a significant risk for organizations relying on Unla for identity mediation or API protection, as it effectively nullifies the expected security boundary for downstream services.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized actors to bypass authentication controls and interact with protected internal resources. Impacted organizations face potential data exfiltration from proxied upstream APIs, unauthorized use of injected credentials, and total compromise of restricted MCP prefixes. The CVSS 3.1 score of 8.2 reflects the high potential for impact on confidentiality and integrity within integrated service environments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize the identification of all instances of AmoyLab Unla within the environment to determine exposure.</li>
<li>Monitor access logs for suspicious OAuth2 client registration activity followed by rapid requests to the /authorize and /token endpoints from unidentified or unauthorized sources.</li>
<li>Update all instances of AmoyLab Unla to a patched version beyond 0.10.0 once available.</li>
<li>Implement additional API gateway-level authentication checks for services proxied behind Unla as a temporary compensatory control until patching can be completed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>