Description
Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers can register a client with the long_lived_access_token scope and lure a user to an authorization link, obtaining a non-expiring API token with the user's full permissions.
Published: 2026-10-11
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the admin OAuth server of Rill, allowing dynamic client registration to consume the long_lived_access_token scope without user consent. Attackers can register a client, provide a user with an OAuth authorization link, and obtain a non‑expiring API token that grants full permissions. The resulting token gives the attacker comprehensive access to the user’s data and services, enabling high‑level privileged actions without detection.

Affected Systems

Affected versions are Rill Data’s Rill open‑source platform from 0.77.0 through 0.90.5 inclusive. Any deployment of those versions running the default OAuth server configuration is vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and although no public EPSS score is available, the absence of an authorization step makes exploitation straightforward via a web request to the OAuth registration endpoint. The vulnerability is not listed in CISA KEV, but its ability to grant persistent, high‑level access without user notice represents a significant threat for exposed instances.

Generated by OpenCVE AI on October 11, 2026 at 13:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Rill to a version that rectifies the OAuth missing‑authorization flaw.
  • If an upgrade is not immediately possible, disable or restrict dynamic client registration in the OAuth server configuration to prevent unauthenticated client creation.
  • Restrict or remove the long_lived_access_token scope from allowed scopes until a patch is applied.

Generated by OpenCVE AI on October 11, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers can register a client with the long_lived_access_token scope and lure a user to an authorization link, obtaining a non-expiring API token with the user's full permissions.
Title Rill 0.77.0 through 0.90.5 OAuth Missing Authorization via Dynamic Client Registration
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:30.004Z

Reserved: 2026-10-11T01:52:16.678Z

Link: CVE-2026-108718

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:15.020

Modified: 2026-10-11T13:17:15.020

Link: CVE-2026-108718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:30:19Z

Weaknesses