Impact
Obot allows an unauthenticated party to gain full administrative control of its API and UI when the Docker quickstart is used with default settings. The service listens on 0.0.0.0:8080 without authentication, mapping every request to a synthetic "nobody" user that holds Owner and Admin privileges. This flaw enables the attacker to register and launch malicious MCP servers and to manipulate the system as an administrator. The weakness stems from improper authentication configuration (CWE-306).
Affected Systems
The vulnerability affects the obot-platform Obot product in all versions up to and including commit d7e6970. Any instance launched via the Docker quickstart instructions in the README that binds the container to all network interfaces on port 8080 is susceptible. The quickstart also mounts /var/run/docker.sock, giving the container access to the host’s Docker control surface.
Risk and Exploitability
The CVSS score of 9.3 classifies this as critical, indicating a devastating impact if exploited. Although the EPSS score is not available, the lack of listed exploits in KEV suggests it has not yet been widely abused, yet the obvious network-level attack surface makes exploitation straightforward for any actor who can reach port 8080. Remote attackers can achieve full administrative access, host compromise via the Docker socket, and injection of attacker-controlled servers.
OpenCVE Enrichment