Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101063— Obot before v0.23.0 Authentication Bypass via Registry API

Quick assessment

Affected
obot-platform obot
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Obot 在 v0.23.0 版本之前,当启用注册表认证时,未能对 /v0.1/* 路径下的 MCP 注册表端点强制执行身份认证。未认证的攻击者可以通过向 /v0.1/servers 发送 GET 请求,读取注册表的元数据,包括服务器名称、描述、仓库 URL 和连接 URL。

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101063

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Obot before v0.23.0 Authentication Bypass via Registry API
Source: CVE Program / CVE List V5
Vulnerability Description
Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and connect URLs by sending GET requests to /v0.1/servers.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
obot-platform obot 0 ~ 0.23.0 -

II. Public POCs for CVE-2026-101063

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101063

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101063 (1)

Other References for CVE-2026-101063 (1)

Same Patch Batch · obot-platform · 2026-09-27 · 5 CVEs total

CVE-2026-101065 9.8 CRITICAL Obot Quickstart Docker Deployment Unauthenticated Admin Access
CVE-2026-101084 9.6 CRITICAL obot before v0.21.1 Authorization Bypass via /mcp-connect
CVE-2026-101062 8.8 HIGH Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
CVE-2026-101064 7.6 HIGH Obot before v0.23.0 Server-Side Request Forgery via MCP

IV. Related Vulnerabilities

V. Comments for CVE-2026-101063

No comments yet


Leave a comment