CVE-2026-101084 debrief based on the supplied source corpus. The CVE record was published on 2026-09-27T21:17:02.163Z and has not been modified since then. The vulnerability affects obot versions before 0.21.1, allowing authenticated users to bypass authorization checks and connect to restricted MCP servers if they possess the server ID. This could lead to unauthorized access and manipulation of sensitive [truncated]
CVE-2026-101065 debrief: Obot platform vulnerable to unauthenticated admin access via exposed Docker quickstart. The Obot platform's Docker quickstart command exposes the container on 0.0.0.0:8080 with authentication disabled by default, granting full administrative access to unauthenticated parties. Operators and administrators of Obot platform deployments, especially those exposing the service to untrus [truncated]
CVE-2026-101064 is a server-side request forgery vulnerability in Obot before v0.23.0 that allows privileged users to specify arbitrary URLs without destination validation, potentially disclosing sensitive credentials. This vulnerability can lead to unauthorized access to internal services and cloud metadata endpoints, resulting in potential credential disclosure and other security risks. Defenders respon [truncated]
CVE-2026-101063 is a medium-severity vulnerability in Obot versions before v0.23.0. Unauthenticated attackers can read registry metadata by sending GET requests to /v0.1/servers due to the failure to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. This issue may expose server names, descriptions, repository URLs, and connect URLs. Defenders responsib [truncated]
CVE-2026-101062 is a high-severity vulnerability in Obot versions before v0.23.0. When authentication is enabled, Obot exposes OAuth dynamic client registration without authentication and without restrictions on redirect URIs. An attacker can register a client with their own domain, induce a logged-in victim to visit a crafted authorization URL, and obtain an authorization code. This code can be exchanged [truncated]