Obot's documented Docker quickstart starts the platform on all network interfaces with authentication turned off, so anyone who can reach the port gets full administrative control and a path to the host's Docker control surface.
What Is It
CVE-2026-101065 is a missing-authentication weakness (CWE-306) in Obot, an open-source AI agent and MCP platform. The Docker quickstart command in the project README starts the container listening on 0.0.0.0:8080, and authentication is disabled by default.
With authentication off, Obot maps every request to a synthetic "nobody" user that holds the Owner and Admin roles. Any unauthenticated party who can reach the exposed port gets full administrative access to the Obot API and UI.
Why It Matters
VulnCheck scored the flaw 9.8 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. It can be exploited over the network with low complexity, and it requires no privileges and no user interaction.
Admin access here goes beyond the application itself. An attacker can register and launch attacker-controlled MCP servers. The quickstart also mounts /var/run/docker.sock into the container, so the MCP runtime backend reachable this way has access to the host's Docker control surface. On an exposed quickstart deployment, an attacker who reaches the open port could use that Docker socket access to affect the underlying host.
As of 2026-09-27, this CVE does not appear in CISA's Known Exploited Vulnerabilities catalog. None of the advisories cited below report active exploitation.
What's Vulnerable
- Vendor/Product: obot-platform / obot
- Affected: all versions up to and including commit
d7e6970, when deployed using the Docker quickstart command documented in the README - Conditions: the container is reachable from an untrusted network, authentication is left disabled (the quickstart default), and
/var/run/docker.sockis mounted as the quickstart instructs
NVD lists the record as "Received". It was published on 2026-09-27 and has no CPE entries yet.
Patch Status
The fix is documentation-only. The README quickstart now enables authentication. No code change is described, so existing deployments stay exposed until operators change their configuration.
Required action: operators who followed the previous quickstart instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network. Deployments that are already reachable without authentication should be treated as fully exposed at the admin level.