{"id":"CVE-2026-103758","summary":"Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route","details":"Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.","aliases":["GHSA-6fwv-3h4c-37j9"],"modified":"2026-10-03T03:45:49.585299112Z","published":"2026-10-01T10:42:26.638Z","database_specific":{"cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103758.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103758.json"},{"type":"ADVISORY","url":"https://github.com/obot-platform/obot/security/advisories/GHSA-6fwv-3h4c-37j9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103758"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/obot-0.21.1-through-0.24.1-authorization-bypass-via-mcp-connect-composite-route"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/obot-platform/obot","events":[{"introduced":"2a2ec3f23ac564b2e2fab6b09fdef4ecd05fd496"},{"fixed":"9903b2d1861952a06b3cc9d0a37b08f23e237f86"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0.21.1"},{"last_affected":"0.24.1"},{"fixed":"0.24.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103758.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}