CVE-2026-105139
Deferred Deferred - Pending Action

Authorization Bypass in Obot 0.26.0 via vMCP Profile

Vulnerability report for CVE-2026-105139, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
obot-platform obot 0.26.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105139 is an authorization bypass vulnerability in Obot platform versions 0.26.0 and 0.26.1. It allows authenticated users with any vMCP profile to access prompts, resources, and resource templates of components they are not explicitly granted access to. This happens because profile restrictions only applied to tools, not prompts or resources. Attackers can exploit shared component connections to reach sensitive data.

Detection Guidance

To detect this vulnerability, check if your Obot platform version is between 0.26.0 and 0.26.1. Use commands like 'obot version' or inspect package files for version details. Verify if vMCPs with profiles are configured and if unauthorized access to prompts or resources is possible.

Impact Analysis

This vulnerability allows unauthorized access to sensitive data via prompts and resources. While tools and credentials remain protected, attackers could view or interact with restricted content through shared vMCP connections. The impact includes potential data leaks or misuse of ungranted resources.

Compliance Impact

The vulnerability allows unauthorized access to sensitive data via prompts and resources through shared component connections. This could lead to violations of data protection regulations like GDPR (which requires strict access controls for personal data) and HIPAA (which mandates safeguards for protected health information). Unauthorized access risks exposing confidential information, potentially resulting in non-compliance with these standards.

Mitigation Strategies

Immediately upgrade Obot to version 0.26.2 or later. This removes ungranted components from user vMCPs. If upgrading is not possible, disable vMCPs with profiles or restrict access to sensitive components until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105139. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart