---
id: CVE-2026-103758
title: >-
  Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that
  allows authenticated users to reach MCP servers because the checkUI deny list
  omits the /mcp-connect-composite/ route
summary: >-
  Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that
  allows authenticated users to reach MCP servers because the checkUI deny list
  omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP
  I…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-863
vendor: obot-platform
product: obot
affected:
  - obot >= 0.21.1 <= 0.24.1
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:26.360'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103758'
references:
  - url: >-
      https://github.com/obot-platform/obot/security/advisories/GHSA-6fwv-3h4c-37j9
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/obot-0.21.1-through-0.24.1-authorization-bypass-via-mcp-connect-composite-route
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.816Z'
---

## Overview

Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
