Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101062— Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration

Quick assessment

Affected
obot-platform obot
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Obot 在 v0.23.0 之前(受影响的版本为 ≤ v0.22.1),当配置了 时,会暴露 OAuth 动态客户端注册功能,且该注册无需身份验证,同时对客户端可注册的回调 URI(redirect URIs)没有任何限制。 由于授权流程在用户已登录的情况下会自动完成,无需经过同意屏幕(consent screen),攻击者可以注册一个指向其自有域名的客户端,并诱导已登录的受害者访问一个精心构造的授权 URL。随后,攻击者将在其控制的回调 URI 上接收到授权码(authorization code),并可将该授

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101062

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
Source: CVE Program / CVE List V5
Vulnerability Description
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own domain and induces a logged-in victim to visit a single crafted authorization URL receives an authorization code at the attacker-controlled redirect URI and can exchange it for an access token and refresh token. The token minted by the MCP OAuth flow carries the victim's full group set in the JWT, and Obot validated only the issuer and not the audience, so the token is accepted as a bearer token against any Obot API endpoint the victim can access rather than being scoped to the requested MCP server, allowing the attacker to read or modify the victim's resources until the token is revoked. v0.23.0 adds a consent screen, restricts MCP OAuth tokens to the MCP involved in the request, and enforces audience validation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
obot-platform obot 0 ~ 0.23.0 -

II. Public POCs for CVE-2026-101062

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101062

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101062 (1)

Other References for CVE-2026-101062 (1)

Same Patch Batch · obot-platform · 2026-09-27 · 5 CVEs total

CVE-2026-101065 9.8 CRITICAL Obot Quickstart Docker Deployment Unauthenticated Admin Access
CVE-2026-101084 9.6 CRITICAL obot before v0.21.1 Authorization Bypass via /mcp-connect
CVE-2026-101064 7.6 HIGH Obot before v0.23.0 Server-Side Request Forgery via MCP
CVE-2026-101063 5.3 MEDIUM Obot before v0.23.0 Authentication Bypass via Registry API

IV. Related Vulnerabilities

V. Comments for CVE-2026-101062

No comments yet


Leave a comment