CVE-2026-101065

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authentication, and operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-09-28)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-27: 1Mentions · 2026-09-28: 209-2709-28
Referenced assets3 URLs
Full discourse3 posts
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Obot: Zwei kritische Schwachstellen ermöglichen Admin-Zugriff und Umgehung von Zugriffskontrollen #cve2026101065 #cve2026101084 #docker #mcp #obot https://cybersecurity-news.de/obot-kritische-schwachstellen-cve-2026-101065-cve-2026-101084

    0000013
    12 followersView on X
  • Severity Daily@severitydaily

    Obot's documented Docker quickstart got a 9.8 CVE, and the fix is a README edit — no version of Obot closes it. The quickstart mounts the Docker socket. No exploitation reported. https://severitydaily.com/obot-cve-2026-101065-docker-quickstart-9-8-fix-documentation-only/

    0000028
    25 followersView on X
  • SecNews@SecNews_GR

    CVE-2026-101065: Κρίσιμο κενό στο Obot αφήνει Docker χωρίς έλεγχο https://www.secnews.gr/736328/cve-2026-101065-obot-docker/?fsp_sid=15197

    00000139
    7.0K followersView on X

Explore more