Critical severity9.6NVD Advisory· Published Sep 27, 2026
CVE-2026-101084
CVE-2026-101084
Description
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <v0.21.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.