Impact
The vulnerability is a missing authorization flaw in the admin OAuth server of Rill, allowing dynamic client registration to consume the long_lived_access_token scope without user consent. Attackers can register a client, provide a user with an OAuth authorization link, and obtain a non‑expiring API token that grants full permissions. The resulting token gives the attacker comprehensive access to the user’s data and services, enabling high‑level privileged actions without detection.
Affected Systems
Affected versions are Rill Data’s Rill open‑source platform from 0.77.0 through 0.90.5 inclusive. Any deployment of those versions running the default OAuth server configuration is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and although no public EPSS score is available, the absence of an authorization step makes exploitation straightforward via a web request to the OAuth registration endpoint. The vulnerability is not listed in CISA KEV, but its ability to grant persistent, high‑level access without user notice represents a significant threat for exposed instances.
OpenCVE Enrichment