CVE-2026-105139 PUBLISHED

Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources

Assigner: VulnCheck
Reserved: 03.10.2026 Published: 07.10.2026 Updated: 07.10.2026

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor obot-platform
Product obot
Versions Default: unaffected
  • affected from 0.26.0 to 0.26.2 (excl.)

Credits

  • Scott Moore - VulnCheck finder

References

Problem Types

  • Incorrect Authorization CWE