Skip to content
feed: live
>_0dayNews
mcp

Obot AI Platform Patches Three CVEs, Two Critical

Three GitHub Security Advisories disclose an unauthenticated Docker exposure and two MCP endpoint access control failures in the Obot AI agent platform.

Obot AI Platform Patches Three CVEs, Two Critical
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·2 min read

The quickstart command documented in the Obot README starts the Docker container bound to 0.0.0.0:8080. No authentication is required. Any machine that can reach that port has full access to the Obot API.

That is the plain description of CVE-2026-101065, scored CVSS 9.8 (critical) and disclosed by the Obot project via GitHub Security Advisory. It affects all versions through commit d7e6970. Obot is an open-source AI agent and MCP (Model Context Protocol) platform. The flaw is documentation-level: the default instruction is the exposure, not a misconfiguration buried in settings.

Two more advisories followed the same day.

CVE-2026-101084 (CVSS 9.6, critical) covers a failure to enforce Access Control Rules on the /mcp-connect endpoint in versions before v0.21.1. The control plane correctly records which users can reach which MCP servers, but the rule was not applied to /mcp-connect. Any authenticated user who knew a restricted server’s ID could connect to it regardless of their assigned access level.

CVE-2026-101063 (CVSS 5.3, medium) covers a separate boundary: in versions before v0.23.0, the MCP Registry endpoints at /v0.1/* do not require authentication even when registry authentication is enabled. Unauthenticated callers can read registry metadata including server listings.

None of the three advisories report active exploitation. All three were disclosed by the Obot project itself, and patches are available. Version v0.21.1 addresses CVE-2026-101084, and v0.23.0 addresses CVE-2026-101063. The Docker binding issue (CVE-2026-101065) requires a configuration change for existing deployments, not just a version upgrade. The advisory recommends binding to 127.0.0.1 or placing a reverse proxy in front of the container for any network-accessible installation.

MCP tooling has drawn recurring access-control findings over the past several months. This site covered ten MCP server CVEs in a single disclosure day in August and a separate authentication bypass in the MCP Memory Service the same week. The LightLLM Config Server disclosed a CVSS 9.8 unauthenticated RCE in September via a similarly exposed default binding. The Obot findings extend that pattern to the orchestration layer itself, not just the MCP servers it connects to.

For teams running Obot: upgrade to v0.23.0 to cover all three advisories, and verify the Docker bind address before any deployment where the container port is reachable outside the host.

Related CVEs
  • [ CRITICAL ]CVE-2026-101065Obot Docker Quickstart Exposes API on All Interfaces Without Auth
  • [ CRITICAL ]CVE-2026-101084Obot /mcp-connect Endpoint Ignores Access Control Rules
  • [ MEDIUM ]CVE-2026-101063Obot MCP Registry Endpoints Unauthenticated When Auth Is Enabled

Found this useful? Share it.