CVE-2026-105139

Source
https://cve.org/CVERecord?id=CVE-2026-105139
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105139.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105139
Aliases
  • GHSA-xhpw-65qw-wj6m
Published
2026-10-07T12:18:33Z
Modified
2026-10-09T02:49:19Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources
Details

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105139.json"
}
References

Affected packages

Git / github.com/obot-platform/obot

Affected ranges

Type
GIT
Repo
https://github.com/obot-platform/obot
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.26.0"
        },
        {
            "fixed": "0.26.2"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.26.0
v0.26.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105139.json"