Authorization Bypass in Obot Affected by Misconfigured vMCP Profiles
CVE-2026-105139

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-105139?

Obot prior to version 0.26.2 is vulnerable to an authorization bypass issue, allowing users with access to any vMCP profile to gain unauthorized access to ungranted components. The vulnerability arises because profile enforcement was limited to tools, leaving prompts, resources, and resource templates exposed. Attackers leveraging this flaw can exploit shared component connections to access restricted functionalities, thus compromising the integrity of the application. Users are advised to upgrade to version 0.26.2 or later to mitigate this risk.

Affected Version(s)

obot 0.26.0 < 0.26.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scott Moore - VulnCheck
.