CVE-2026-101064
Received Received - Intake

Obot Remote Server Registration SSRF Vulnerability

Vulnerability report for CVE-2026-101064, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
obot obot to 0.23.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Obot before v0.23.0 has a server-side request forgery (SSRF) vulnerability in remote MCP server registration. Privileged users can register MCP servers with arbitrary URLs without validation. Attackers with Power User or higher roles can force Obot to send requests to internal services or cloud metadata endpoints. Responses may leak sensitive credentials in error messages.

Detection Guidance

To detect this SSRF vulnerability in Obot, monitor network traffic for outbound requests from Obot servers to internal or unexpected external endpoints. Check Obot logs for remote MCP server registration attempts with unusual URLs. Inspect error messages for leaked credentials or internal service responses.

Impact Analysis

An attacker with sufficient privileges could access internal services, exfiltrate sensitive data like credentials, or interact with cloud metadata endpoints to gather further information. This could lead to unauthorized access, data breaches, or lateral movement within a network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if credentials or personal data are exposed due to this flaw.

Mitigation Strategies

Upgrade Obot to version 0.23.0 or later to address the server-side request forgery vulnerability in remote MCP server registration. Restrict user roles to prevent Power User or higher from registering arbitrary URLs. Validate and restrict URL destinations in MCP server registration to internal or trusted services only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101064. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart