Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-101065

Obot Docker Quickstart Exposes API on All Interfaces Without Auth

The Obot AI agent platform Docker quickstart binds to 0.0.0.0:8080 by default, exposing the full API without authentication to any host that can reach the port.

cat cve-2026-101065.json
Vendor
Obot Platform
Product
Obot (all versions through commit d7e6970)
CVSS
9.8
EPSS (exploit probability)
N/A
Status
patched
Published

The Obot README’s Docker quickstart command starts the container listening on 0.0.0.0:8080, binding to all network interfaces without authentication. Any host that can reach that port can access the full Obot API.

Mitigation requires binding to 127.0.0.1 or placing a reverse proxy with authentication in front of the container. The project disclosed this via GitHub Security Advisory GHSA-jj4w-pfgv-4mrm.