CVE-2026-101084
Received Received - Intake

Authentication Bypass in obot MCP Connect Endpoint

Vulnerability report for CVE-2026-101084, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability exists in obot versions before v0.21.1 where Access Control Rules are not enforced on the /mcp-connect endpoint. This allows any authenticated user with a server ID to bypass authorization checks and connect to restricted MCP servers. Attackers can then use stored OAuth credentials to access and manipulate sensitive backend systems through MCP tool calls.

Impact Analysis

An attacker could gain unauthorized access to sensitive backend systems, potentially leading to data breaches, unauthorized data manipulation, or further lateral movement within the network. This could result in loss of confidential data, system integrity issues, or compliance violations depending on the data accessed.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations may face regulatory penalties, legal liabilities, and reputational damage if such a breach occurs due to non-compliance with these standards.

Mitigation Strategies

Upgrade obot to version v0.21.1 or later to enforce Access Control Rules on the /mcp-connect endpoint. Ensure only authorized users can access restricted MCP servers by validating server IDs and permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101084. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart