CVE-2026-103758 - Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route
CVE ID :CVE-2026-103758 Published : Oct. 1, 2026, 10:42 a.m. | 35 minutes ago Description :Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route....