CVE-2026-105139
Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.
| CWE | CWE-863 |
| Vendor | obot-platform |
| Product | obot |
| Published | Oct 7, 2026 |
| Last Updated | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for obot-platform obot
Be the first to know when new medium vulnerabilities affecting obot-platform obot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
obot-platform / obot
0.26.0 < 0.26.2
References
github.com: https://github.com/obot-platform/obot/commit/8d92701c2018a7b9dd6d692498fa5f41fdb912ea github.com: https://github.com/obot-platform/obot github.com: https://github.com/obot-platform/obot/security/advisories/GHSA-xhpw-65qw-wj6m github.com: https://github.com/obot-platform/obot/releases/tag/v0.26.2 github.com: https://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L97 github.com: https://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L231 vulncheck.com: https://www.vulncheck.com/advisories/obot-0.26.0-before-0.26.2-authorization-bypass-via-vmcp-profile-prompts-and-resources
Credits
Scott Moore - VulnCheck