Insufficiently Protected Credentials Vulnerability in Obot by Obot Platform
CVE-2026-105138
7.1HIGH
What is CVE-2026-105138?
The Obot product, specifically versions prior to 0.26.2, suffers from a vulnerability where authenticated users can access static secrets stored on the MCP catalog entries. This flaw allows basic users with specific access rights to make GET requests to the API, retrieving plaintext API keys or tokens that were intended to be secured. Exploitation of this vulnerability can lead to unauthorized actions on backend services, highlighting a significant risk to data integrity and application security.
Affected Version(s)
obot 0.12.0 < 0.26.2
