HIGH 8.6 NVD
CVE-2026-103758
Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omi
Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.
References
- https://github.com/obot-platform/obot/security/advisories/GHSA-6fwv-3h4c-37j9
- https://www.vulncheck.com/advisories/obot-0.21.1-through-0.24.1-authorization-bypass-via-m
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.