---
id: CVE-2026-105138
title: >-
  Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials
  vulnerability that allows authenticated users to read static secrets set on
  MCP catalog entries by admins or power users
summary: >-
  Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials
  vulnerability that allows authenticated users to read static secrets set on
  MCP catalog entries by admins or power users. Basic users granted an entry by
  access c…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: obot-platform
product: obot
affected:
  - obot >= 0.12.0 < 0.26.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:46.333'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105138'
references:
  - url: 'https://github.com/obot-platform/obot'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/authz/resources.go#L27
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/handlers/mcp.go#L206-L212
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/commit/644a1fd60a66125ced3de10b350a983e933def7a
    label: disclosure@vulncheck.com
  - url: 'https://github.com/obot-platform/obot/releases/tag/v0.26.2'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/security/advisories/GHSA-q5wf-87f5-cxgq
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/obot-0.12.0-before-0.26.2-credential-exposure-via-mcp-catalog-entry-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T16:06:30.356028Z'
ingestedAt: '2026-10-07T13:31:04.595Z'
---

## Overview

Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
