CVE-2026-101065
published 2026-09-27CVE-2026-101065: Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.44%
35.8th percentile
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authentication, and operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| obot-platform | obot | <= * | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
obot-platform Obot Quickstart OBOT_SERVER_ENABLE_AUTHENTICATION improper authentication (d7e6970 / EUVD-2026-88030)
vuldb·2026-09-27·CVSS 9.8
CVE-2026-101065 [CRITICAL] obot-platform Obot Quickstart OBOT_SERVER_ENABLE_AUTHENTICATION improper authentication (d7e6970 / EUVD-2026-88030)
A vulnerability, which was classified as critical, has been found in obot-platform Obot. This affects an unknown function of the component Quickstart. The manipulation of the argument OBOT_SERVER_ENABLE_AUTHENTICATION leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-101065. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.
GHSA
Obot is an open-source AI agent/MCP platform.
ghsa_unreviewed·2026-09-27
CVE-2026-101065 [CRITICAL] CWE-306 Obot is an open-source AI agent/MCP platform.
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authenticati
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-27
Published