CVE-2026-54618: Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user

Published Sep 17, 2026
·
Updated

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULTMCPTOKEN without authenticating a client. An unauthenticated remote caller who can reach the intended tunnel deployment can therefore call /mcp and use vaultread, vaultwrite, vaultsearch, vaultlist, vaultmove, and vaultdelete against the entire vault. Optional PKCE does not prevent an attacker-initiated flow, and unauthenticated /oauth/register also exposes a clientcredentials path by returning the configured VAULTOAUTHCLIENTSECRET. This issue is fixed in version 0.2.0.

Affected Software

1 affected component
Obsidian Web MCP<0.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Obsidian Web MCP to a version that resolves this vulnerability.

    Fixed in 0.2.0

Event History

Sep 17, 2026
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated remote access?

Deployments running versions prior to 0.2.0 are exposed if an unauthenticated remote caller can reach the intended tunnel deployment. No account, existing session, client authentication, or user interaction is required.

2

What can an attacker do after exploiting the OAuth endpoints?

An attacker can obtain the static VAULT_MCP_TOKEN and call /mcp against the entire vault. Available actions include reading, writing, searching, listing, moving, and deleting vault content.

3

Does enabling PKCE prevent exploitation?

No. PKCE is optional and does not stop an attacker from initiating their own authorization flow.

4

Are there additional affected OAuth paths beyond authorization-code exchange?

Yes. The unauthenticated /oauth/register endpoint returns the configured VAULT_OAUTH_CLIENT_SECRET, exposing a client_credentials path without authentication.

5

What version fixes the issue?

Upgrade Obsidian Web MCP to version 0.2.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203