What happened
NVD published this on 2026-09-27 (VulnCheck): the Docker quickstart documented in the Obot README starts the container on 0.0.0.0:8080 with authentication disabled by default, so every request maps to a synthetic owner/admin user. Because the quickstart also mounts the host Docker socket, the MCP runtime reachable this way has the host Docker control surface. CVSS 9.8 (v3.1) / 9.3 (v4.0).
Why it matters
This is an AI agent/MCP gateway where 'launch an agentic workload' translates directly into host-level Docker access. An unauthenticated attacker gets full admin on the Obot API/UI, can register and launch attacker-controlled MCP servers, and via the mounted Docker socket can pivot to host compromise — the default install is trivially exploitable.
Attack vector
Unauthenticated HTTP access to the documented Docker quickstart, which binds 0.0.0.0:8080 with authentication disabled; every request is mapped to a synthetic 'nobody' user holding Owner/Admin roles, and the container mounts /var/run/docker.sock, giving the reachable MCP runtime access to the host's Docker control plane.
Affected systems
obot-platform/obot, all versions up to commit d7e6970 (docs-only fix; operators must set OBOT_SERVER_ENABLE_AUTHENTICATION=true)
Mitigation
Upgrade to the fixed quickstart docs and set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposure; restrict network access to the service. Advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-jj4w-pfgv-4mrm