Vulnerability  ·  2026-10-08

Obot: insufficiently protected MCP catalog secrets let basic users read admin-stored static credentials (CVE-2026-105138)

VulnerabilityMedium impactGlobalCVE-2026-105138
NVD published CVE-2026-105138 (CVSS 6.5) on 2026-10-07 for an insufficiently-protected-credentials flaw in Obot: basic users granted an entry by access control rules can read static secrets on MCP catalog entries via the corresponding API endpoint, exposing credentials set by admins or power users.
Obot is a multi-agent control plane where MCP catalog entries bundle real API credentials; exposing those static secrets to low-privileged users leaks the exact keys those MCP tools authenticate with, enabling lateral access to the connected external services beyond Obot itself.
An authenticated basic user, granted access to an MCP catalog entry, reads the entry resource including the static secrets (API keys/credentials) that an admin or power user configured for that MCP server.
Obot 0.12.0 before 0.26.2
Upgrade Obot to 0.26.2 or later; restrict which roles receive MCP catalog entries that carry static secrets.
NVD CVE-2026-105138Obot repository
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →