{"data":{"id":"c55bd569-6df5-43cc-b94f-f4e84134ef24","title":"CVE-2026-101065: Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart ","summary":"Obot, an open-source AI agent platform, had a security flaw in its Docker quickstart instructions where the application started without authentication enabled, meaning anyone accessing port 8080 could gain full administrative control and potentially run malicious code on the host system. The vulnerability affected all versions up to commit d7e6970 because the default setup gave unauthenticated users the highest privilege levels (Owner and Admin roles) and mounted the host's Docker control socket into the container.","solution":"The fix is documentation-only: the quickstart now enables authentication by default. Operators who used the previous instructions should set the environment variable OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101065","publishedAt":"2026-09-27T21:17:02.027Z","cveId":"CVE-2026-101065","cweIds":["CWE-306"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Obot"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-27T21:17:02.027Z","capecIds":["CAPEC-115"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}