Sceawere
Vulnerability Detail
CVE-2026-101063UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Obot MCP Registry Authentication Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 11h ago
- Vendor
- obot-platform
- Product
- obot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and connect URLs by sending GET requests to /v0.1/servers.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-27T21:17:01.757Z",
"pubdate": "2026-09-27T21:17:01.757Z",
"executiveSummary": "Obot versions prior to v0.23.0 contain an authentication bypass vulnerability within the MCP Registry component.\nThe vulnerability manifests as a failure to enforce authorization checks on specific API endpoints under the /v0.1/* path when registry authentication is enabled.\nThis flaw allows unauthenticated, remote attackers to perform unauthorized read operations on sensitive registry metadata.\nThe impact includes the exposure of architectural information, specifically server names, descriptions, repository URLs, and internal connect URLs.\nThis vulnerability is particularly critical in environments where the registry is intended to be private, as it circumvents the intended security controls to reveal potentially sensitive infrastructure topology.\nThe exploitation requirement is minimal, as it involves only standard GET requests sent to the vulnerable endpoint by an attacker with network access to the Obot instance.\nNo elevated privileges or specialized credentials are required to carry out this information disclosure.",
"technicalDetails": "The vulnerability resides in the Obot MCP Registry module, which provides management and discovery services for Model Context Protocol (MCP) servers.\nThe root cause is a deficiency in the middleware or access control logic responsible for mediating requests to the /v0.1/* API routing namespace.\nAlthough Obot supports registry-wide authentication, the implementation fails to apply this authentication guard to the discovery endpoints, most notably /v0.1/servers.\nUnder normal operating conditions, an authenticated session should be required to query the registry. However, the application logic incorrectly treats requests to the /v0.1/ namespace as public, regardless of the registry authentication configuration state.\nThe attack flow is straightforward: an unauthenticated actor identifies an Obot instance with a reachable MCP Registry interface. The actor then crafts an HTTP GET request directed at the /v0.1/servers endpoint.\nBecause the backend authentication middleware is bypassed, the application processes the request and returns a JSON-formatted response containing the full list of registered MCP servers.\nThis metadata response includes detailed internal information, such as server descriptions, repository locations, and connection strings required for clients to interface with these servers.\nThe exposure of this data facilitates reconnaissance, allowing attackers to map the internal service structure, identify the existence of specific backend tools, and potentially target those tools for secondary attacks if they contain their own vulnerabilities.\nThe issue persists in all versions of Obot released prior to v0.23.0.\nThe vulnerability is fully network-accessible, meaning any entity capable of routing packets to the Obot instance can perform this information gathering without needing to authenticate, effectively rendering the registry's security configurations for these endpoints inert."
}