CVE-2026-105139: fallo de gravedad media en obot-platform obot
Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
obot-platform · obotCVEs relacionadas — obot-platform obot
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-101065CRITICALObot Quickstart Docker Deployment Unauthenticated Admin AccessEPSS 0.4%CVE-2026-101062HIGHObot before v0.23.0 Authentication Bypass via OAuth Dynamic Client RegistrationEPSS 0.3%CVE-2026-101084CRITICALobot before v0.21.1 Authorization Bypass via /mcp-connectEPSS 0.3%CVE-2026-101063MEDIUMObot before v0.23.0 Authentication Bypass via Registry APIEPSS 0.2%CVE-2026-101064HIGHObot before v0.23.0 Server-Side Request Forgery via MCPEPSS 0.2%CVE-2026-103758HIGHObot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ RouteEPSS 0.2%
Referencias
https://github.com/obot-platform/obothttps://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L231https://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L97https://github.com/obot-platform/obot/commit/8d92701c2018a7b9dd6d692498fa5f41fdb912eahttps://github.com/obot-platform/obot/releases/tag/v0.26.2https://github.com/obot-platform/obot/security/advisories/GHSA-xhpw-65qw-wj6mhttps://www.vulncheck.com/advisories/obot-0.26.0-before-0.26.2-authorization-bypass-via-vmcp-profile-prompts-and-resources