---
cve: "CVE-2026-101084"
severity: "CRITICAL"
cvss: 9.3
epss: "0.3%"
vendor: "obot-platform"
kev: false
exploited: false
published: "2026-09-27 21:17:02"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-02T00:57:00+02:00"
---

# CVE-2026-101084

> 9.3 CRITICAL · 🧪 PoC

## Beschreibung

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulnCheck**
- State: PUBLISHED
- Stand: 2026-09-27 20:49:56
- CNA-CVSS: **9.3** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N`)

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 2a2ec3f23ac564b2e2fab6b09fdef4ecd05fd496 (Commit)

## Referenzen

- <https://github.com/obot-platform/obot/security/advisories/GHSA-vw82-7fv8-r6gp>
- <https://www.vulncheck.com/advisories/obot-before-0.21.1-authorization-bypass-via-mcp-connect>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-101084) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
