CVE-2026-101062

Source
https://cve.org/CVERecord?id=CVE-2026-101062
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101062.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101062
Aliases
Published
2026-09-27T20:49:54Z
Modified
2026-09-29T03:45:44Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
Details

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own domain and induces a logged-in victim to visit a single crafted authorization URL receives an authorization code at the attacker-controlled redirect URI and can exchange it for an access token and refresh token. The token minted by the MCP OAuth flow carries the victim's full group set in the JWT, and Obot validated only the issuer and not the audience, so the token is accepted as a bearer token against any Obot API endpoint the victim can access rather than being scoped to the requested MCP server, allowing the attacker to read or modify the victim's resources until the token is revoked. v0.23.0 adds a consent screen, restricts MCP OAuth tokens to the MCP involved in the request, and enforces audience validation.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-863"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101062.json"
}
References

Affected packages

Git / github.com/obot-platform/obot

Affected ranges

Type
GIT
Repo
https://github.com/obot-platform/obot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.23.0"
        },
        {
            "fixed":  "v0.23.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.0-rc1
v0.1.0-rc2
v0.1.0-rc3
v0.1.0-rc4
v0.10.0
v0.11.0
v0.11.0-rc1
v0.12.0
v0.12.0-rc1
v0.13.0
v0.13.0-rc1
v0.13.0-rc2
v0.15.0
v0.15.0-rc1
v0.15.1
v0.15.1-rc1
v0.16.0
v0.16.0-rc1
v0.16.1
v0.16.2
v0.17.0
v0.17.0-rc1
v0.17.0-rc2
v0.17.1
v0.18.0
v0.18.0-rc1
v0.18.1
v0.18.2-rc1
v0.19.0
v0.19.0-rc1
v0.2.0
v0.2.0-rc1
v0.2.1
v0.20.0
v0.20.0-rc1
v0.20.0-rc2
v0.20.1
v0.21.0
v0.21.0-rc1
v0.21.0-rc2
v0.22.0
v0.22.0-alpha1
v0.22.0-alpha2
v0.22.0-alpha3
v0.22.0-alpha4
v0.22.0-alpha5
v0.22.0-alpha6
v0.22.0-alpha7
v0.22.0-alpha8
v0.22.0-rc1
v0.22.0-rc2
v0.22.0-rc3
v0.22.1
v0.23.0-rc1
v0.23.0-rc2
v0.23.0-rc3
v0.23.0-rc4
v0.23.0-rc5
v0.3.0
v0.4.0
v0.4.0-rc1
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.8.0
v0.8.0-rc1
v0.8.0-rc2
v0.8.0-rc3
v0.9.0
v0.9.0-rc1
v0.9.1-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101062.json"