Sceawere
Vulnerability Detail
CVE-2026-108718UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Rill Admin OAuth Authorization Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 4h ago
- Vendor
- Rill Data
- Product
- rill
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers can register a client with the long_lived_access_token scope and lure a user to an authorization link, obtaining a non-expiring API token with the user's full permissions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-11T13:17:15.020Z",
"pubdate": "2026-10-11T13:17:15.020Z",
"executiveSummary": "Rill versions 0.77.0 through 0.90.5 are susceptible to a missing authorization vulnerability within the admin OAuth server component.\nThe flaw allows unauthorized third-party clients to undergo dynamic registration and subsequently issue authorization codes without requiring explicit user consent.\nAn attacker can leverage this oversight by registering a malicious client with the 'long_lived_access_token' scope and luring an authenticated user to follow a crafted authorization URL.\nSuccessful exploitation results in the unauthorized generation of a non-expiring API token, effectively granting the attacker the full permissions and access rights associated with the victim's account.\nThis vulnerability poses a critical risk to data confidentiality and integrity, as it bypasses standard OAuth security boundaries, permitting persistent account takeover without physical or credential access by the attacker.\nExploitation requires no prior authentication from the attacker but necessitates social engineering to ensure a victim interacts with the malicious authorization link.",
"technicalDetails": "The vulnerability resides in the Rill admin OAuth server's implementation of dynamic client registration and token issuance workflows.\nThe core issue is a missing authorization check, specifically the failure to enforce mandatory user consent during the OAuth authorization grant process for dynamically registered clients.\nIn a secure OAuth implementation, the Authorization Server must verify user approval before issuing an authorization code. In the affected versions of Rill, the server skips this validation step for clients registered via the dynamic registration endpoint.\nAttackers can programmatically register a client via the admin interface and request the 'long_lived_access_token' scope, which grants elevated, persistent access to the Rill platform.\nThe attack flow follows these steps: 1) The attacker initiates dynamic client registration to receive a Client ID and secret. 2) The attacker crafts an authorization URL directed to the Rill OAuth server, requesting the sensitive 'long_lived_access_token' scope. 3) The attacker performs social engineering to trick an authenticated user into clicking this URL. 4) Because the server lacks the required authorization logic, it processes the request automatically without triggering the expected consent screen. 5) The server issues an authorization code, which is then exchanged by the attacker for a non-expiring API token.\nBecause the issued token is long-lived, the attacker gains indefinite access to the victim's resources and API functionalities. This bypasses the typical security controls afforded by short-lived access tokens and standard revocation workflows.\nThe vulnerability affects the admin OAuth server component in Rill versions 0.77.0 through 0.90.5. The exposure is network-accessible, as the OAuth endpoints must be reachable to facilitate the redirection flow.\nPost-exploitation, the attacker assumes the identity of the victim within the Rill environment, with the ability to perform any action the victim is authorized to execute, potentially leading to unauthorized data exfiltration, project modification, or administrative privilege abuse."
}