CVE-2026-105139: Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources
Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who matches any vMCP profile can exploit it. The user does not need to have been granted access to the affected component, prompts, resources, or resource templates.
What data or functionality can be reached through the bypass?
The bypass exposes prompts, resources, and resource templates belonging to ungranted components. Access occurs through the vMCP owner's shared component connection.
Are vMCP profiles fully affected?
Profiles were enforced on tools only, not on prompts, resources, or resource templates. Environments using vMCP profiles with shared component connections are therefore affected by this authorization gap.
Which versions are affected?
Obot 0.26.0 before 0.26.2 is affected. Upgrading to 0.26.2 or later addresses the affected version range.