What happened
NVD published CVE-2026-105138 (CVSS 6.5) on 2026-10-07 for an insufficiently-protected-credentials flaw in Obot: basic users granted an entry by access control rules can read static secrets on MCP catalog entries via the corresponding API endpoint, exposing credentials set by admins or power users.
Why it matters
Obot is a multi-agent control plane where MCP catalog entries bundle real API credentials; exposing those static secrets to low-privileged users leaks the exact keys those MCP tools authenticate with, enabling lateral access to the connected external services beyond Obot itself.
Attack vector
An authenticated basic user, granted access to an MCP catalog entry, reads the entry resource including the static secrets (API keys/credentials) that an admin or power user configured for that MCP server.
Affected systems
Obot 0.12.0 before 0.26.2
Mitigation
Upgrade Obot to 0.26.2 or later; restrict which roles receive MCP catalog entries that carry static secrets.