Medium severity4.3NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-105139
CVE-2026-105139
Description
Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.26.2
Patches
Vulnerability mechanics
References
6- github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.gonvd
- github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.gonvd
- github.com/obot-platform/obot/commit/8d92701c2018a7b9dd6d692498fa5f41fdb912eanvd
- github.com/obot-platform/obot/releases/tag/v0.26.2nvd
- github.com/obot-platform/obot/security/advisories/GHSA-xhpw-65qw-wj6mnvd
- www.vulncheck.com/advisories/obot-0.26.0-before-0.26.2-authorization-bypass-via-vmcp-profile-prompts-and-resourcesnvd
News mentions
0No linked articles in our index yet.