PT-2026-99712 · Bot · Bot
CVE-2026-101084
·
Published
2026-05-13
·
Updated
2026-10-02
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
bot versions prior to 0.21.1
Description
An authorization bypass exists in the gateway endpoint
/mcp-connect/{mcp id} where Access Control Rules (ACRs) are not enforced. Any authenticated user who possesses a specific MCP Server ID can connect to that server and execute tool calls, regardless of whether they have been granted permission through an MCP Registry. This allows users to bypass intended restrictions and manipulate sensitive backend systems using the platform's stored OAuth credentials.Recommendations
Update bot to version 0.21.1 or later.
As a temporary mitigation, restrict access to the
/mcp-connect endpoint to only authorized administrative users.Exploit
Fix
IDOR
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bot