{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rill/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rilldata:rill:0.77.0:*:*:*:*:*:*:*","cpe:2.3:a:rilldata:rill:0.90.5:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-108718"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Rill (0.77.0-0.90.5)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rill"],"content_html":"\u003cp\u003eRill versions 0.77.0 through 0.90.5 are affected by a missing authorization vulnerability within the admin OAuth server component. This flaw permits the dynamic registration of OAuth clients that can request elevated scopes, such as long_lived_access_token, without obtaining explicit user consent. An attacker can exploit this by registering a malicious client and tricking a legitimate user into visiting a crafted authorization link. Upon the user's interaction, the system issues a non-expiring API token directly to the attacker-controlled client, granting the attacker the user's full permissions. This vulnerability enables persistent access and potential exfiltration of sensitive analytics or metadata managed within the Rill environment. Organizations utilizing Rill versions 0.77.0 to 0.90.5 are at risk of complete account takeover if users interact with attacker-supplied authorization links.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized generation of non-expiring API tokens, granting attackers persistent access to user data and Rill platform resources. This can lead to significant data exfiltration, unauthorized modification of analytics configurations, and loss of environment control. The severity is highlighted by a CVSS v3.1 base score of 8.1, reflecting high potential for unauthorized access and privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Rill to a version beyond 0.90.5 immediately to patch CVE-2026-108718.\u003c/li\u003e\n\u003cli\u003eAudit OAuth client registrations in Rill administrative logs for any unexpected or dynamically registered client IDs initiated during the period of exposure.\u003c/li\u003e\n\u003cli\u003eReview logs for OAuth authorization requests where the requested scope includes long_lived_access_token and the client was not pre-approved or vetted by administrative policy.\u003c/li\u003e\n\u003cli\u003eImplement stricter access control policies for dynamic client registration to prevent unauthorized third-party integrations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T14:01:20Z","date_published":"2026-10-11T14:01:20Z","id":"https://feed.craftedsignal.io/briefs/2026-10-rill-oauth-vuln/","summary":"Rill versions 0.77.0 through 0.90.5 contain a missing authorization vulnerability that allows attackers to obtain non-expiring API tokens with elevated permissions via unauthorized OAuth code issuance.","title":"Missing Authorization Vulnerability in Rill Admin OAuth Server","url":"https://feed.craftedsignal.io/briefs/2026-10-rill-oauth-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Rill","version":"https://jsonfeed.org/version/1.1"}