External risk intelligence

Obsidian Web MCP Authorization and Token Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-54618

The product is designed as a remote server for Obsidian vaults and operates via web-based OAuth and API endpoints (/oauth/authorize, /mcp). Because its primary function is to facilitate remote access to data, it is commonly deployed as an internet-facing web service or API, making it reachable by external callers.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Obsidian Web MCP, a secure remote server for Obsidian vaults. This issue allows unauthenticated remote attackers to access and manipulate vault data, potentially leading to unauthorized data access or modification. The primary concern is confirming the relevance and exposure of this technology within our environment.

  • Unauthenticated remote vault data access.
  • Critical if Obsidian Web MCP is in use.
  • Assess relevance and exposure; take action.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can gain full access to an Obsidian vault by sending specially crafted requests to the /oauth/authorize and /oauth/token endpoints. These endpoints incorrectly issue authorization codes and exchange them for a static token, bypassing necessary checks. If successful, an attacker could read, write, search, list, move, or delete vault data.

  • No authentication needed for access.
  • Bypasses login and consent checks.
  • Full vault data compromise.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote caller could gain unauthorized access to an Obsidian vault's data and perform actions such as reading, writing, searching, listing, moving, and deleting files. This could occur when the system's /oauth/authorize and /oauth/token endpoints are improperly handled, allowing the static VAULT_MCP_TOKEN to be exchanged without proper authentication or consent. The optional PKCE mechanism does not prevent this flow, and an unauthenticated /oauth/register endpoint may also expose client credentials.

  • Vault data integrity and confidentiality.
  • Unauthenticated remote access to sensitive operations.
  • Complete vault data compromise or modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Obsidian Web MCP product, used for secure remote access to Obsidian vaults, is likely managed by application owners or platform teams responsible for deployed services. The initial step is to locate all instances of this technology, verify their network reachability and business criticality, identify the accountable owner, and then prioritize remediation based on the assessed risk.

  • Application owners should address this.
  • Verify public exposure and asset criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Obsidian Web MCP?

Obsidian Web MCP acts as a bridge, allowing you to access and manage your Obsidian vault remotely through a web server. It translates requests from external tools into operations on your local vault files, such as reading or modifying notes, by leveraging OAuth for connection handling and standard API calls to interact with your data.

What is the vulnerability in CVE-2026-54618?

This flaw is primarily a lack of authentication (CWE-306) and improper credential management. Essentially, the software's authorization and token endpoints fail to verify identity, consent, or sessions. Because these gates are left open, an attacker can obtain the vault's static access token without logging in and perform destructive or unauthorized actions on your files.

Does enabling PKCE protect me from this bug?

No, enabling Proof Key for Code Exchange (PKCE) does not prevent this vulnerability. The flaw exists because the endpoints themselves do not require authentication or valid session checks before issuing tokens. Since the attacker can initiate the flow without credentials, the security mechanisms meant to protect the exchange are effectively bypassed.

How likely is it that my instance is reachable by outsiders?

Halo Surface Signal indicates that because Obsidian Web MCP is designed as a remote server, it is often deployed as an internet-facing service to facilitate remote vault access. This means if your instance is accessible from the public internet, it is inherently reachable by external, unauthenticated callers who could exploit these endpoints.

How do I secure my environment against this issue?

Your first step is to identify where you are running Obsidian Web MCP and determine who owns the deployment. Once located, prioritize updating the software to version 0.2.0, which resolves these authentication failures. If you cannot update immediately, restrict network access to the server to prevent remote, unauthenticated traffic from reaching the affected endpoints.

References