{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/obot--0.23.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:obot:obot:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-101065"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Obot (\u003c= d7e6970)","obot (\u003c 0.21.1)","Obot (\u003c= 0.22.1)","Obot (\u003c 0.23.0)"],"_cs_severities":["critical"],"_cs_tags":["authorization-bypass","cve","mcp","authentication-bypass","oauth","cve-2026-101062","cloud"],"_cs_type":"advisory","_cs_vendors":["Obot"],"content_html":"\u003cp\u003eObot, an open-source AI agent and Model Context Protocol (MCP) platform, contains a critical security misconfiguration in its documented Docker quickstart procedure affecting all versions up to and including commit d7e6970. The default configuration exposes the application on 0.0.0.0:8080 without enabling authentication. By design, unauthenticated requests are assigned to a synthetic 'nobody' user that possesses both Owner and Admin roles within the platform.\u003c/p\u003e\n\u003cp\u003eThis allows any attacker with network reach to the exposed port to gain full administrative control over the Obot API and UI. Furthermore, the quickstart documentation instructs users to mount the host's /var/run/docker.sock into the container. Attackers gaining administrative access through the Obot interface can leverage this mounted socket to interact with the host's Docker engine, potentially leading to container breakout and full host system compromise. The issue is addressed by updated documentation that mandates enabling authentication via the OBOT_SERVER_ENABLE_AUTHENTICATION environment variable.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain full administrative access to the Obot platform. Due to the mounting of the host Docker socket, an attacker can escalate privileges from the application level to the host operating system. This vulnerability affects any deployment that followed the standard quickstart instructions without manually overriding the default authentication settings.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize securing Obot deployments immediately following the documentation update.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSet the environment variable OBOT_SERVER_ENABLE_AUTHENTICATION=true for all existing Obot containers.\u003c/li\u003e\n\u003cli\u003eReview network perimeter controls to ensure the Obot UI and API (port 8080) are not exposed to untrusted networks.\u003c/li\u003e\n\u003cli\u003eVerify container mounts to ensure that sensitive host resources, specifically /var/run/docker.sock, are restricted or removed if not strictly required for platform functionality.\u003c/li\u003e\n\u003cli\u003eAudit existing Obot logs for unauthorized API access or registry of external MCP servers occurring from unknown or unauthorized client IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T23:11:12Z","date_published":"2026-09-27T23:10:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-obot-misconfiguration/","summary":"Obot versions up to commit d7e6970 contain a default configuration vulnerability that exposes the application with administrative privileges and Docker socket access to unauthenticated network actors.","title":"Obot Docker Quickstart Authentication Misconfiguration","url":"https://feed.craftedsignal.io/briefs/2026-09-obot-misconfiguration/"}],"language":"en","title":"CraftedSignal Threat Feed - Obot (\u003c 0.23.0)","version":"https://jsonfeed.org/version/1.1"}