Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Obot-platform
Obot-platform obot |
|
| Vendors & Products |
Obot-platform
Obot-platform obot |
Wed, 07 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services. | |
| Title | Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API | |
| Weaknesses | CWE-522 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T12:35:49.041Z
Reserved: 2026-10-03T13:40:47.067Z
Link: CVE-2026-105138
No data.
Status : Deferred
Published: 2026-10-07T13:17:16.977
Modified: 2026-10-07T13:17:19.150
Link: CVE-2026-105138
No data.
OpenCVE Enrichment
Updated: 2026-10-07T13:30:16Z
Weaknesses