Vulnerability  ·  2026-09-28

Obot /mcp-connect authorization bypass lets any authenticated user reach restricted MCP servers

VulnerabilityHigh impactGlobalCVE-2026-101084
NVD published on 2026-09-27 (VulnCheck): obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. CVSS 9.6 (v3.1).
This breaks the tenant/privilege boundary of an agent platform that brokers MCP connections to sensitive backend systems (databases, internal APIs). A low-privilege user in an Obot tenant can reach restricted MCP servers and operate them with the platform's stored OAuth credentials — a direct agentic-infrastructure authorization bypass.
An authenticated user sends a request to /mcp-connect with a known server ID of a restricted MCP server; the endpoint fails to enforce Access Control Rules, and the attacker then drives MCP tool calls using the system's stored OAuth credentials against the target backend.
obot-platform/obot < v0.21.1 (pkg:golang/github.com/obot-platform/obot)
Upgrade to obot v0.21.1 or later, which enforces access-control rules on /mcp-connect. Advisory: https://github.com/obot-platform/obot/security/advisories/GHSA-vw82-7fv8-r6gp
NVD CVE-2026-101084GitHub Security Advisory GHSA-vw82-7fv8-r6gpVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →