CVE-2026-101065
Published 27 September 2026 · tracked since 28 September 2026
Description
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-100894 MEDIUM 6.3
- CVE-2026-100895 MEDIUM 5.3
- CVE-2026-100898 MEDIUM 6.3
- CVE-2026-100890 MEDIUM 5.3
- CVE-2026-100891 HIGH 7.3
- CVE-2026-100887 MEDIUM 6.3
- CVE-2026-100888 HIGH 7.3
- CVE-2026-100889 HIGH 7.3
- CVE-2026-100883 MEDIUM 6.3
- CVE-2026-100884 MEDIUM 4.3