PT-2026-99711 · Obot · Obot
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Obot versions up to and including commit d7e6970
Description
The Docker quickstart command starts the container listening on 0.0.0.0:8080 with authentication disabled by default. In this state, every request is mapped to a synthetic "nobody" user possessing Owner and Admin roles. This allows any unauthenticated party with access to the exposed port to gain full administrative access to the API and UI, enabling the registration and launch of attacker-controlled MCP (Model Context Protocol) servers. Additionally, because the quickstart mounts
/var/run/docker.sock into the container, the MCP runtime backend can access the host's Docker control surface.Recommendations
Set
OBOT SERVER ENABLE AUTHENTICATION to true before exposing the host to any untrusted network.Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Obot