Get real-time updates on Telegram
Verified
CVE-2026-105139: obot 0.26.0 to before 0.26.2
Affected technology
obot · 0.26.0 to before 0.26.2
obot-platform
Description’s affected range: before 0.26.2
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
The source says because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality impact as low; integrity and availability impact as none.
- CWE
- CWE-863
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 13:38:49.647974+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-105139.html