CVE-2026-101084: obot before v0.21.1 Authorization Bypass via /mcp-connect
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
obotto a version that resolves this vulnerability.Fixed in 0.21.1
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated Obot user can exploit it if they know the ID of a restricted MCP server. No additional privileges or user interaction are required.
What access could an attacker gain through a successful exploit?
An attacker can connect to restricted MCP servers and invoke MCP tools using stored OAuth credentials. This can provide access to and allow manipulation of sensitive backend systems exposed through those tools.
Which deployments are affected?
Obot versions before v0.21.1 are affected. The issue concerns the /mcp-connect endpoint when Access Control Rules are expected to restrict access to MCP servers.