Skip to content
feed: live
>_0dayNews
CVE Record
[ MEDIUM ]CVE-2026-101063

Obot MCP Registry Endpoints Unauthenticated When Auth Is Enabled

Obot before v0.23.0 does not enforce authentication on MCP Registry endpoints at /v0.1/* even when registry auth is configured, exposing server listings to unauthenticated callers.

cat cve-2026-101063.json
Vendor
Obot Platform
Product
Obot (before v0.23.0)
CVSS
5.3
EPSS (exploit probability)
N/A
Status
patched
Published

When registry authentication is enabled in Obot, the MCP Registry API endpoints under /v0.1/* still accept unauthenticated requests. Callers can read registry metadata including the list of registered MCP servers without credentials.

Fixed in Obot v0.23.0. Disclosed via GitHub Security Advisory GHSA-pr6h-vr44-xq8j.