HIGH
AmoyLab
CVE published 2026-10-11
CVE-2026-108865
CVE-2026-108865 AmoyLab Unla through 0.10.0 OAuth2 Authentication Bypass via /authorize allows unauthenticated attackers to obtain valid access tokens due to the OAuth2 server never authenticating a resource owner. This vulnerability impacts AmoyLab Unla deployments using OAuth2 for authentication, enabling unauthorized access to protected MCP prefixes, proxied upstream APIs, and potential credential inje [truncated]