CVE-2026-101084 PUBLISHED

obot before v0.21.1 Authorization Bypass via /mcp-connect

Assigner: VulnCheck
Reserved: 27.09.2026 Published: 27.09.2026 Updated: 27.09.2026

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 9.3

Product Status

Vendor obot-platform
Product obot
Versions Default: unaffected
  • affected from 0 to 0.21.1 (excl.)
  • Version 0.21.1 is unaffected

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE