Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101065— Obot Quickstart Docker Deployment Unauthenticated Admin Access

Quick assessment

Affected
obot-platform obot
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Obot 是一个开源的 AI Agent / MCP(Model Context Protocol)平台。在包含提交 d7e6970 在内的所有版本中,README 文档中记录的 Docker 快速启动命令会将容器绑定到 0.0.0.0:8080,并且默认禁用身份验证。当身份验证被禁用时,所有请求都会被映射到一个名为“nobody”的合成用户,该用户拥有 Owner(所有者)和 Admin(管理员)角色。因此,任何能够访问该暴露端口的未认证用户都能获得对 Obot API 和 UI 的完全管理员访问权限,包括注册和

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101065

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Obot Quickstart Docker Deployment Unauthenticated Admin Access
Source: CVE Program / CVE List V5
Vulnerability Description
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authentication, and operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
obot-platform obot - -

II. Public POCs for CVE-2026-101065

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101065

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101065 (1)

Other References for CVE-2026-101065 (1)

Same Patch Batch · obot-platform · 2026-09-27 · 5 CVEs total

CVE-2026-101084 9.6 CRITICAL obot before v0.21.1 Authorization Bypass via /mcp-connect
CVE-2026-101062 8.8 HIGH Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
CVE-2026-101064 7.6 HIGH Obot before v0.23.0 Server-Side Request Forgery via MCP
CVE-2026-101063 5.3 MEDIUM Obot before v0.23.0 Authentication Bypass via Registry API

IV. Related Vulnerabilities

V. Comments for CVE-2026-101065

No comments yet


Leave a comment