CVE-2026-101084

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-28: 109-28
Referenced assets1 URL
Full discourse1 post
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Obot: Zwei kritische Schwachstellen ermöglichen Admin-Zugriff und Umgehung von Zugriffskontrollen #cve2026101065 #cve2026101084 #docker #mcp #obot https://cybersecurity-news.de/obot-kritische-schwachstellen-cve-2026-101065-cve-2026-101084

    0000013
    12 followersView on X

Explore more