Cyber & AI intelligence
Wasteland.
Briefs indexed2904
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101084 2026-09-27

Obot Authorization Bypass Exposes Restricted MCP Servers (CVE-2026-101084)

"Obot versions before v0.21.1 don't enforce Access Control Rules on the `/mcp-connect` endpoint, so any authenticated user who knows a server ID can connect to a restricted MCP server."

Obot versions before v0.21.1 don't enforce Access Control Rules on the /mcp-connect endpoint, so any authenticated user who knows a server ID can connect to a restricted MCP server.

What Is It

CVE-2026-101084 is an authorization bypass in obot, an obot-platform project distributed as the Go package github.com/obot-platform/obot. Obot doesn't apply its Access Control Rules to the /mcp-connect endpoint. Any authenticated user who has a restricted MCP server's ID can connect to that server, even without permission to use it.

The weakness is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). The server ID is the key the user controls, and it's the only thing standing between a low-privileged user and a restricted server.

Why It Matters

The advisory says attackers can use this bypass to access and manipulate sensitive backend systems through MCP tool calls. Those calls run with OAuth credentials already stored in obot. So an ordinary account can end up acting with whatever access those credentials grant on connected backend systems.

VulnCheck, the CNA, scores the flaw as critical:

The attack works over the network, has low complexity, needs only low privileges and requires no user interaction. The scope is Changed, which fits the risk to backend systems beyond obot. Confidentiality and integrity impacts are High, and there is no availability impact.

Exploitation status: The supplied CISA KEV data has no entry for this CVE, so active exploitation is not confirmed. NVD lists the record as "Received," which means NVD has not analyzed it yet.

What's Vulnerable

The NVD record lists no CPEs.

Patch Status

Version 0.21.1 is listed as unaffected. Organizations running obot should upgrade to v0.21.1 or later.

Because no KEV entry exists, there is no CISA-mandated required action or due date. Given the critical score and the exposure of stored OAuth credentials, upgrade quickly anyway. Check which MCP servers are marked restricted and which backend credentials they hold, then read the vendor advisory for further guidance.

Sources