CVE-2026-101084
Obot Authorization Bypass via MCP Connect Endpoint
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability exists in obot that allows authenticated users to bypass access controls on the /mcp-connect endpoint. This could enable attackers to access and manipulate sensitive backend systems using stored credentials.