Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-101084

Obot /mcp-connect Endpoint Ignores Access Control Rules

Obot before v0.21.1 fails to enforce access control rules on /mcp-connect, letting any authenticated user connect to restricted MCP servers by supplying the server ID.

cat cve-2026-101084.json
Vendor
Obot Platform
Product
Obot (before v0.21.1)
CVSS
9.6
EPSS (exploit probability)
N/A
Status
patched
Published

Obot’s control plane records per-user MCP server access rules, but those rules were not applied to the /mcp-connect endpoint in versions before v0.21.1. Any authenticated user who obtained a restricted server’s ID could bypass access controls and connect directly.

Fixed in Obot v0.21.1. Disclosed via GitHub Security Advisory GHSA-vw82-7fv8-r6gp.