CVE-2026-101065
Received Received - Intake

Obot Platform Authentication Bypass via Docker Quickstart

Vulnerability report for CVE-2026-101065, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authentication, and operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
obot obot to d7e6970 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Obot is an open-source AI agent/MCP platform vulnerable in versions up to commit d7e6970. The Docker quickstart command starts the container listening on 0.0.0.0:8080 with authentication disabled by default. This allows unauthenticated parties to gain full administrative access to the Obot API and UI, including registering and launching attacker-controlled MCP servers. The quickstart also mounts /var/run/docker.sock, giving the MCP runtime backend access to the host's Docker control surface.

Detection Guidance

Check if the Obot container is running with the Docker quickstart command and exposing port 8080 without authentication. Inspect the container configuration for mounted /var/run/docker.sock and disabled authentication. Use commands like 'docker ps' to list running containers and 'docker inspect <container>' to verify settings.

Impact Analysis

An attacker who can reach the exposed port can gain full administrative access to the Obot API and UI. They can register and launch malicious MCP servers, which have access to the host's Docker control surface due to the mounted socket. This could lead to unauthorized control over the host system and potential compromise of other services.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's security and privacy rules. Unauthorized administrative access may result in exposure of sensitive data, non-compliance with access controls, and failure to meet regulatory standards for data security and integrity.

Mitigation Strategies

Set OBOT_SERVER_ENABLE_AUTHENTICATION=true in the Obot container configuration. Ensure the container is not exposed to untrusted networks. Update the Docker quickstart command to enable authentication as per the fixed documentation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101065. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart