Vulnerability  ·  2026-09-28

Obot AI agent/MCP platform Docker quickstart: unauthenticated full admin access with host Docker socket exposed

VulnerabilityHigh impactGlobalCVE-2026-101065
NVD published this on 2026-09-27 (VulnCheck): the Docker quickstart documented in the Obot README starts the container on 0.0.0.0:8080 with authentication disabled by default, so every request maps to a synthetic owner/admin user. Because the quickstart also mounts the host Docker socket, the MCP runtime reachable this way has the host Docker control surface. CVSS 9.8 (v3.1) / 9.3 (v4.0).
This is an AI agent/MCP gateway where 'launch an agentic workload' translates directly into host-level Docker access. An unauthenticated attacker gets full admin on the Obot API/UI, can register and launch attacker-controlled MCP servers, and via the mounted Docker socket can pivot to host compromise — the default install is trivially exploitable.
Unauthenticated HTTP access to the documented Docker quickstart, which binds 0.0.0.0:8080 with authentication disabled; every request is mapped to a synthetic 'nobody' user holding Owner/Admin roles, and the container mounts /var/run/docker.sock, giving the reachable MCP runtime access to the host's Docker control plane.
obot-platform/obot, all versions up to commit d7e6970 (docs-only fix; operators must set OBOT_SERVER_ENABLE_AUTHENTICATION=true)
Upgrade to the fixed quickstart docs and set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposure; restrict network access to the service. Advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-jj4w-pfgv-4mrm
NVD CVE-2026-101065GitHub Security Advisory GHSA-jj4w-pfgv-4mrmVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →