Authorization Bypass in Obot Affected by Misconfigured vMCP Profiles
CVE-2026-105139
5.3MEDIUM
What is CVE-2026-105139?
Obot prior to version 0.26.2 is vulnerable to an authorization bypass issue, allowing users with access to any vMCP profile to gain unauthorized access to ungranted components. The vulnerability arises because profile enforcement was limited to tools, leaving prompts, resources, and resource templates exposed. Attackers leveraging this flaw can exploit shared component connections to access restricted functionalities, thus compromising the integrity of the application. Users are advised to upgrade to version 0.26.2 or later to mitigate this risk.
Affected Version(s)
obot 0.26.0 < 0.26.2
