CVE-2026-105138

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 6,5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none

Description

AI Translation Available

Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.

522

Insufficiently Protected Credentials

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies: Not Technology-Specific, Web Based, ICS/OT
View CWE Details
https://github.com/obot-platform/obot
https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859…
https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859…
https://github.com/obot-platform/obot/commit/644a1fd60a66125ced3de10b350a983e93…
https://github.com/obot-platform/obot/releases/tag/v0.26.2
https://github.com/obot-platform/obot/security/advisories/GHSA-q5wf-87f5-cxgq
https://www.vulncheck.com/advisories/obot-0.12.0-before-0.26.2-credential-expos…