← Back to search

CVE-2026-101062

8.8 HIGHpublic exploit available

Published 2026-09-27 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows an attacker to register an OAuth client without authentication, leading to unauthorized access to the victim's resources via a crafted authorization URL.
Exploitability
Exploitation is moderately hard as it requires an attacker to register a client and induce a logged-in victim to visit a crafted URL. Precondition is the victim must be logged in to the affected version of Obot.
Blast radius
If exploited, the attacker can read or modify the victim's resources until the token is revoked, potentially leading to significant data breaches.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Obot v0.23.0 or later.
auth-bypasswebjwtoauth

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own domain and induces a logged-in victim to visit a single crafted authorization URL receives an authorization code at the attacker-controlled redirect URI and can exchange it for an access token and refresh token. The token minted by the MCP OAuth flow carries the victim's full group set in the JWT, and Obot validated only the issuer and not the audience, so the token is accepted as a bearer token against any Obot API endpoint the victim can access rather than being scoped to the requested MCP server, allowing the attacker to read or modify the victim's resources until the token is revoked. v0.23.0 adds a consent screen, restricts MCP OAuth tokens to the MCP involved in the request, and enforces audience validation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-863

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.