{"id":"CVE-2026-108718","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-108718","summary":"Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent.…","details":"Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers can register a client with the long_lived_access_token scope and lure a user to an authorization link, obtaining a non-expiring API token with the user's full permissions.","published":"2026-10-11T13:17:15.020","modified":"2026-10-11T13:17:15.020","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/rilldata/rill"},{"type":"WEB","url":"https://github.com/rilldata/rill/blob/b9ea8c6f215e56c4c0848771e70b3ec38346eacc/admin/server/auth/handlers.go#L650-L697"},{"type":"WEB","url":"https://github.com/rilldata/rill/blob/b9ea8c6f215e56c4c0848771e70b3ec38346eacc/admin/server/auth/mcp_oauth.go#L77-L153"},{"type":"WEB","url":"https://github.com/rilldata/rill/blob/b9ea8c6f215e56c4c0848771e70b3ec38346eacc/admin/server/auth/pkce.go#L173-L214"},{"type":"WEB","url":"https://hackmd.io/@haind03/rill-oauth-open-registration-long-lived-token"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/rill-0.77.0-through-0.90.5-oauth-missing-authorization-via-dynamic-client-registration"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-11T13:17:15.020"}}