Unauthenticated Access Vulnerability in Obot AI Agent Platform
CVE-2026-101065
9.3CRITICAL
What is CVE-2026-101065?
The Obot AI agent/MCP platform has a vulnerability that arises when the Docker quickstart command is executed without enabling authentication by default. This allows any unauthenticated user to access the platform, thereby gaining full administrative privileges to the Obot API and UI. Specifically, the vulnerability allows unauthorized parties to register and control malicious instances of MCP servers. The quickstart also poses a risk as it mounts the host's Docker control surface into the container, potentially exposing critical host operations. Users are advised to enable authentication by setting the parameter OBOT_SERVER_ENABLE_AUTHENTICATION=true to mitigate this risk.
