Unauthenticated Access Vulnerability in Obot AI Agent Platform
CVE-2026-101065

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101065?

The Obot AI agent/MCP platform has a vulnerability that arises when the Docker quickstart command is executed without enabling authentication by default. This allows any unauthenticated user to access the platform, thereby gaining full administrative privileges to the Obot API and UI. Specifically, the vulnerability allows unauthorized parties to register and control malicious instances of MCP servers. The quickstart also poses a risk as it mounts the host's Docker control surface into the container, potentially exposing critical host operations. Users are advised to enable authentication by setting the parameter OBOT_SERVER_ENABLE_AUTHENTICATION=true to mitigate this risk.

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.