CVE-2026-101084
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Summary
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| obot-platform | obot | 0 < 0.21.1 | affected |
| obot-platform | obot | 0.21.1 | unaffected |
Weaknesses
- CWE-639: Authorization Bypass Through User-Controlled Key
References
- https://github.com/obot-platform/obot/security/advisories/GHSA-vw82-7fv8-r6gp
- https://www.vulncheck.com/advisories/obot-before-0.21.1-authorization-bypass-via-mcp-connect
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.