Description
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
Published: 2026-09-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Authorization Bypass allowing authenticated users to connect to restricted MCP servers
Action: Immediate Patch
AI Analysis

Impact

obots before version v0.21.1 do not enforce the required access control on the /mcp-connect endpoint. This flaw allows any authenticated user to connect to any MCP server for which they know the server ID, bypassing normal authorization checks. An attacker who has authenticated credentials can then send MCP tool calls that use stored OAuth tokens, enabling manipulation or discovery of sensitive backend system resources. The impact is a loss of confidentiality and integrity for backend services protected by MCP.

Affected Systems

Affected products are obot from obot-platform. All releases prior to v0.21.1 are vulnerable. The vulnerability affects the obot Platform where the /mcp-connect endpoint is exposed to authenticated users.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The EPSS score is not available, so the historical exploitation likelihood cannot be quantified from this data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user who can request a connection to a restricted MCP by simply knowing the target server ID. An attacker can thus gain unauthorized backend access, potentially performing malicious operations using the existing OAuth credentials.

Generated by OpenCVE AI on September 27, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade obot to v0.21.1 or newer to enforce proper access control on /mcp-connect.
  • Restrict or disable the /mcp-connect endpoint for unprivileged users, or restrict it to trusted IP ranges.
  • Rotate OAuth tokens associated with MCP servers to prevent abuse if credentials were compromised.
  • Monitor logs for unexpected /mcp-connect requests and unauthorized MCP tool activity.

Generated by OpenCVE AI on September 27, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
Title obot before v0.21.1 Authorization Bypass via /mcp-connect
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T20:49:56.702Z

Reserved: 2026-09-27T20:29:07.432Z

Link: CVE-2026-101084

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T21:17:02.163

Modified: 2026-09-27T21:17:02.163

Link: CVE-2026-101084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T23:00:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key