CVE-2026-101063
Received Received - Intake

Obot MCP Registry Authentication Bypass Before v0.23.0

Vulnerability report for CVE-2026-101063, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and connect URLs by sending GET requests to /v0.1/servers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Obot versions before v0.23.0 have an authentication bypass issue in MCP Registry endpoints under /v0.1/*. When registry authentication is enabled, unauthenticated attackers can access registry metadata by sending GET requests to /v0.1/servers. This includes server names, descriptions, repository URLs, and connect URLs.

Detection Guidance

To detect this vulnerability, check if unauthenticated GET requests to /v0.1/servers return registry metadata. Use curl to test endpoints like: curl -X GET http://<target>/v0.1/servers. If metadata is returned without authentication, the system is vulnerable.

Impact Analysis

An attacker could exploit this to gather sensitive information about your Obot registry setup without authentication. This may include details about servers, repositories, and connections, potentially aiding further attacks or reconnaissance.

Compliance Impact

This vulnerability allows unauthenticated access to registry metadata, which could expose sensitive server names, descriptions, and repository URLs. This may violate data protection requirements under GDPR and HIPAA if such metadata includes personal or health-related information.

Mitigation Strategies

Upgrade Obot to v0.23.0 or later to enforce authentication on MCP Registry endpoints. If immediate upgrade is not possible, restrict access to /v0.1/* paths via network policies or firewall rules until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101063. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart