Authentication Bypass Vulnerability in Obot by Obot Platform
CVE-2026-101063

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101063?

Obot versions prior to 0.23.0 have a security flaw where authentication is not enforced on the MCP Registry endpoints located at /v0.1/*. This issue can be exploited by unauthenticated attackers who can send GET requests to the /v0.1/servers endpoint, allowing them to access sensitive registry metadata such as server names, descriptions, repository URLs, and connect URLs. Proper authentication mechanisms should be implemented to protect against unauthorized access and ensure the integrity of registry data.

Affected Version(s)

obot 0 < 0.23.0

obot 0.23.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hewei-gikaku
.