Description
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authentication, and operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
Published: 2026-09-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized administrative access through exposed Docker container
Action: Patch immediately
AI Analysis

Impact

Obot allows an unauthenticated party to gain full administrative control of its API and UI when the Docker quickstart is used with default settings. The service listens on 0.0.0.0:8080 without authentication, mapping every request to a synthetic "nobody" user that holds Owner and Admin privileges. This flaw enables the attacker to register and launch malicious MCP servers and to manipulate the system as an administrator. The weakness stems from improper authentication configuration (CWE-306).

Affected Systems

The vulnerability affects the obot-platform Obot product in all versions up to and including commit d7e6970. Any instance launched via the Docker quickstart instructions in the README that binds the container to all network interfaces on port 8080 is susceptible. The quickstart also mounts /var/run/docker.sock, giving the container access to the host’s Docker control surface.

Risk and Exploitability

The CVSS score of 9.3 classifies this as critical, indicating a devastating impact if exploited. Although the EPSS score is not available, the lack of listed exploits in KEV suggests it has not yet been widely abused, yet the obvious network-level attack surface makes exploitation straightforward for any actor who can reach port 8080. Remote attackers can achieve full administrative access, host compromise via the Docker socket, and injection of attacker-controlled servers.

Generated by OpenCVE AI on September 27, 2026 at 22:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure Obot to enable authentication before starting the Docker quickstart by setting OBOT_SERVER_ENABLE_AUTHENTICATION=true in the environment or configuration file.
  • Ensure the service does not bind to all interfaces – restrict the listening address or limit exposure of port 8080 to trusted networks using firewalls or segmentation.
  • If possible, remove or protect the Docker socket mount so the container cannot access the host’s Docker control surface.

Generated by OpenCVE AI on September 27, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authentication, and operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
Title Obot Quickstart Docker Deployment Unauthenticated Admin Access
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T20:49:56.009Z

Reserved: 2026-09-27T16:38:56.428Z

Link: CVE-2026-101065

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T21:17:02.027

Modified: 2026-09-27T21:17:02.027

Link: CVE-2026-101065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T22:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function