{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/amoylab/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:amoylab:unla:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-108865"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Unla (\u003c= 0.10.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["AmoyLab"],"content_html":"\u003cp\u003eAmoyLab Unla, an OAuth2 server implementation, contains a critical authentication bypass vulnerability (CVE-2026-108865) affecting versions 0.10.0 and earlier. The security flaw stems from the server's failure to properly authenticate the resource owner during the OAuth2 authorization flow. This defect allows unauthenticated attackers to register their own client, initiate an authorization request, and successfully exchange it for valid access tokens via the /token endpoint.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation enables an attacker to gain unauthorized access to OAuth2-protected Model Context Protocol (MCP) prefixes and proxied upstream APIs. Furthermore, attackers can gain access to credentials injected into these proxied services. Given the nature of the vulnerability as an authentication bypass, it represents a significant risk for organizations relying on Unla for identity mediation or API protection, as it effectively nullifies the expected security boundary for downstream services.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to bypass authentication controls and interact with protected internal resources. Impacted organizations face potential data exfiltration from proxied upstream APIs, unauthorized use of injected credentials, and total compromise of restricted MCP prefixes. The CVSS 3.1 score of 8.2 reflects the high potential for impact on confidentiality and integrity within integrated service environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize the identification of all instances of AmoyLab Unla within the environment to determine exposure.\u003c/li\u003e\n\u003cli\u003eMonitor access logs for suspicious OAuth2 client registration activity followed by rapid requests to the /authorize and /token endpoints from unidentified or unauthorized sources.\u003c/li\u003e\n\u003cli\u003eUpdate all instances of AmoyLab Unla to a patched version beyond 0.10.0 once available.\u003c/li\u003e\n\u003cli\u003eImplement additional API gateway-level authentication checks for services proxied behind Unla as a temporary compensatory control until patching can be completed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T16:03:06Z","date_published":"2026-10-11T16:03:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-amoylab-unla-auth-bypass/","summary":"AmoyLab Unla versions 0.10.0 and earlier are vulnerable to an authentication bypass in the OAuth2 implementation that permits unauthenticated attackers to obtain valid access tokens and interact with restricted APIs.","title":"Authentication Bypass in AmoyLab Unla","url":"https://feed.craftedsignal.io/briefs/2026-10-amoylab-unla-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - AmoyLab","version":"https://jsonfeed.org/version/1.1"}