PatchSiren

AmoyLab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH AmoyLab CVE published 2026-10-11

CVE-2026-108865

CVE-2026-108865 AmoyLab Unla through 0.10.0 OAuth2 Authentication Bypass via /authorize allows unauthenticated attackers to obtain valid access tokens due to the OAuth2 server never authenticating a resource owner. This vulnerability impacts AmoyLab Unla deployments using OAuth2 for authentication, enabling unauthorized access to protected MCP prefixes, proxied upstream APIs, and potential credential inje [truncated]