๐Ÿ” CVE Alert

CVE-2026-105139

MEDIUM 4.3

Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.

CWE CWE-863
Vendor obot-platform
Product obot
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for obot-platform obot

Be the first to know when new medium vulnerabilities affecting obot-platform obot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

obot-platform / obot
0.26.0 < 0.26.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/obot-platform/obot/commit/8d92701c2018a7b9dd6d692498fa5f41fdb912ea github.com: https://github.com/obot-platform/obot github.com: https://github.com/obot-platform/obot/security/advisories/GHSA-xhpw-65qw-wj6m github.com: https://github.com/obot-platform/obot/releases/tag/v0.26.2 github.com: https://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L97 github.com: https://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L231 vulncheck.com: https://www.vulncheck.com/advisories/obot-0.26.0-before-0.26.2-authorization-bypass-via-vmcp-profile-prompts-and-resources

Credits

Scott Moore - VulnCheck