<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Obot (&lt;= D7e6970) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/obot--d7e6970/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 27 Sep 2026 23:10:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/obot--d7e6970/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Obot Docker Quickstart Authentication Misconfiguration</title><link>https://feed.craftedsignal.io/briefs/2026-09-obot-misconfiguration/</link><pubDate>Sun, 27 Sep 2026 23:10:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-obot-misconfiguration/</guid><description>Obot versions up to commit d7e6970 contain a default configuration vulnerability that exposes the application with administrative privileges and Docker socket access to unauthenticated network actors.</description><content:encoded><![CDATA[<p>Obot, an open-source AI agent and Model Context Protocol (MCP) platform, contains a critical security misconfiguration in its documented Docker quickstart procedure affecting all versions up to and including commit d7e6970. The default configuration exposes the application on 0.0.0.0:8080 without enabling authentication. By design, unauthenticated requests are assigned to a synthetic 'nobody' user that possesses both Owner and Admin roles within the platform.</p>
<p>This allows any attacker with network reach to the exposed port to gain full administrative control over the Obot API and UI. Furthermore, the quickstart documentation instructs users to mount the host's /var/run/docker.sock into the container. Attackers gaining administrative access through the Obot interface can leverage this mounted socket to interact with the host's Docker engine, potentially leading to container breakout and full host system compromise. The issue is addressed by updated documentation that mandates enabling authentication via the OBOT_SERVER_ENABLE_AUTHENTICATION environment variable.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to gain full administrative access to the Obot platform. Due to the mounting of the host Docker socket, an attacker can escalate privileges from the application level to the host operating system. This vulnerability affects any deployment that followed the standard quickstart instructions without manually overriding the default authentication settings.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize securing Obot deployments immediately following the documentation update.</p>
<ul>
<li>Set the environment variable OBOT_SERVER_ENABLE_AUTHENTICATION=true for all existing Obot containers.</li>
<li>Review network perimeter controls to ensure the Obot UI and API (port 8080) are not exposed to untrusted networks.</li>
<li>Verify container mounts to ensure that sensitive host resources, specifically /var/run/docker.sock, are restricted or removed if not strictly required for platform functionality.</li>
<li>Audit existing Obot logs for unauthorized API access or registry of external MCP servers occurring from unknown or unauthorized client IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>authorization-bypass</category><category>cve</category><category>mcp</category><category>authentication-bypass</category><category>oauth</category><category>cve-2026-101062</category><category>cloud</category></item></channel></rss>