CVE-2026-103758
Received Received - Intake

Authorization Bypass in Obot MCP Server Access

Vulnerability report for CVE-2026-103758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
obot obot From 0.21.1 (inc) to 0.24.1 (inc)
obot-platform obot From 0.21.1 (inc) to 0.24.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Obot versions 0.21.1 through 0.24.1 have an authorization bypass flaw where authenticated users, including those with basic roles, can access restricted MCP servers via the /mcp-connect-composite/ route. The checkUI deny list fails to include this route, allowing users with a composite MCP ID to proxy requests through mcpGateway.Proxy and invoke tools on servers protected by Access Control Rules.

Detection Guidance

Check for unauthorized access to the /mcp-connect-composite/{mcp_id} route by reviewing web server or application logs for requests to this path. Look for basic-role users making proxy requests through mcpGateway.Proxy to MCP servers. Verify if the deny list in checkUI includes both /mcp-connect/ and /mcp-connect-composite/ routes.

Impact Analysis

This vulnerability allows unauthorized users to interact with MCP servers that should be restricted, potentially leading to data breaches, unauthorized actions, or misuse of server resources. Attackers could exploit this to access sensitive data or perform actions beyond their intended permissions.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations by enabling unauthorized access to sensitive data. It may result in data breaches, violating confidentiality requirements and exposing organizations to legal penalties or reputational damage.

Mitigation Strategies

Update obot to a patched version where the deny list in checkUI includes the /mcp-connect-composite/{mcp_id} route. Alternatively, modify the deny list to cover both /mcp-connect/ and its composite counterpart by adjusting the prefix check. Restrict access to MCP servers by default and explicitly allow only authorized routes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart