What happened
VulnCheck published CVE-2026-108865 (published 2026-10-11, CVSS 8.2 v3.1 / 8.8 v4.0, CWE-287) for AmoyLab Unla ≤ 0.10.0: the OAuth2 server issues tokens without ever authenticating a resource owner, so the /authorize→/token flow yields valid credentials without any login. Verified against NVD REST API.
Why it matters
This is a total authentication bypass on an MCP gateway/agent infrastructure component. Because the stolen token grants access to OAuth2-protected MCP tools and proxied upstream APIs plus injected credentials, an unauthenticated remote attacker can invoke MCP tooling and reach backend AI/data services the deployment was meant to protect — attacker-controlled agent access in real deployments.
Attack vector
Unauthenticated attacker registers an OAuth2 client against the Unla server, requests a code from /authorize, and exchanges it at /token — the authorization server never authenticates the resource owner — yielding a valid access token that unlocks OAuth2-protected MCP prefixes, proxied upstream APIs and injected credentials.
Affected systems
AmoyLab Unla through 0.10.0 (golang: github.com/amoylab/unla)
Mitigation
Upgrade past 0.10.0 and re-test OAuth2 flows; treat all MCP prefixes/upstream APIs as exposed until rotated/patched. Advisory: https://www.vulncheck.com/advisories/amoylab-unla-through-0.10.0-oauth2-authentication-bypass-via-authorize