PT-2026-99709 · Obot · Obot

·

CVE-2026-101063

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Obot versions prior to 0.23.0
Description When registry authentication is enabled via the OBOT SERVER ENABLE REGISTRY AUTH variable, the software fails to enforce authentication on MCP Registry endpoints under the /v0.1/* path. This occurs because the authorizer uses a fixed set of protected prefixes and default-allows others; since the /v0.1 prefix was missing from this set, anonymous requests were authorized before reaching the authentication challenge. Unauthenticated attackers can send GET requests to the /v0.1/servers endpoint to read registry metadata, including server names, descriptions, repository URLs, and connect URLs. This issue does not expose credential values, and unauthenticated users cannot connect to the servers as the connection process remains protected.
Recommendations Upgrade to version 0.23.0 or later.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101063
GHSA-PR6H-VR44-XQ8J
GO-2026-6525

Affected Products

Obot