Description
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own domain and induces a logged-in victim to visit a single crafted authorization URL receives an authorization code at the attacker-controlled redirect URI and can exchange it for an access token and refresh token. The token minted by the MCP OAuth flow carries the victim's full group set in the JWT, and Obot validated only the issuer and not the audience, so the token is accepted as a bearer token against any Obot API endpoint the victim can access rather than being scoped to the requested MCP server, allowing the attacker to read or modify the victim's resources until the token is revoked. v0.23.0 adds a consent screen, restricts MCP OAuth tokens to the MCP involved in the request, and enforces audience validation.
Published: 2026-09-27
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Authorization bypass leading to token theft
Action: Immediate patch
AI Analysis

Impact

Obot before v0.23.0 (versions up to 0.22.1) permits OAuth dynamic client registration to be performed without any authentication and does not restrict the redirect URIs that a client may register. The authorization flow automatically completes for an already logged‑in user without showing a consent screen. An attacker can register a client that points to the attacker’s own domain, lure a victim to visit a single crafted authorization URL, obtain an authorization code at the attacker‑controlled redirect URI, and exchange that code for an access token and a refresh token. The token produced by the MCP OAuth flow contains the victim’s full group set in its JWT payload, and Obot verifies only the issuer, not the audience. Consequently, the attacker can use the token as a bearer token against any Obot API endpoint the victim can access, enabling the attacker to read or modify the victim’s resources until the token is revoked. The flaw satisfies CWE‑863, where a privilege dependency is exploited to bypass authorization.

Affected Systems

The issue affects the obot-platform’s obot product, specifically versions 0.22.1 and earlier when OBOT_SERVER_ENABLE_AUTHENTICATION is set to true. Users running these versions are vulnerable unless the dynamic client registration feature is disabled.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7 and is not listed in the CISA KEV catalog. EPSS data is not available, but the lack of any authentication or redirect‑URI restrictions means an attacker only needs social engineering to get a victim to visit a crafted URL; no local privilege or code execution is required beyond the normal OAuth authorization flow. Once the attacker obtains the victim’s token, the flawed token validation logic allows the attacker to act with the victim’s privileges across all accessible APIs. Given the high impact and the fairly straightforward exploit path, the overall risk is high, especially for environments that rely on Obot’s authorization mechanisms.

Generated by OpenCVE AI on September 27, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to obot v0.23.0 or later, which adds a consent screen, restricts tokens to the MCP involved, and enforces audience validation.
  • If upgrade cannot occur immediately, disable dynamic client registration or block the endpoint that creates new OAuth clients.
  • If disabling is impractical, restrict redirect URIs to known domains and enforce audience validation manually or via external policy while monitoring for unauthorized client registrations.

Generated by OpenCVE AI on September 27, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own domain and induces a logged-in victim to visit a single crafted authorization URL receives an authorization code at the attacker-controlled redirect URI and can exchange it for an access token and refresh token. The token minted by the MCP OAuth flow carries the victim's full group set in the JWT, and Obot validated only the issuer and not the audience, so the token is accepted as a bearer token against any Obot API endpoint the victim can access rather than being scoped to the requested MCP server, allowing the attacker to read or modify the victim's resources until the token is revoked. v0.23.0 adds a consent screen, restricts MCP OAuth tokens to the MCP involved in the request, and enforces audience validation.
Title Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T20:49:54.008Z

Reserved: 2026-09-27T16:38:56.428Z

Link: CVE-2026-101062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T21:17:01.617

Modified: 2026-09-27T21:17:01.617

Link: CVE-2026-101062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T22:30:17Z

Weaknesses