CVE-2026-101084
published 2026-09-27CVE-2026-101084: obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP…
PriorityP260critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.28%
18.5th percentile
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| obot-platform | obot | < 0.21.1 | 0.21.1 |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
obot-platform Obot up to 0.21.0 MCP Connect Endpoint access control (EUVD-2026-88029)
vuldb·2026-09-27·CVSS 9.6
CVE-2026-101084 [CRITICAL] obot-platform Obot up to 0.21.0 MCP Connect Endpoint access control (EUVD-2026-88029)
A vulnerability was found in obot-platform Obot up to 0.21.0. It has been classified as critical. Affected by this issue is some unknown functionality of the component MCP Connect Endpoint. Performing a manipulation results in improper access controls.
This vulnerability is identified as CVE-2026-101084. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID.
ghsa_unreviewed·2026-09-27
CVE-2026-101084 [CRITICAL] CWE-639 obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID.
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-27
Published