# Obot CVE-2026-103758: MCP Gateway Authorization Bypass

> LLM-readable article card for ThreatFrontier.com. Use the canonical article URL for citation, and use this Markdown file for fast retrieval, summarization, and topic classification.

## Canonical Source
- [Canonical article](https://threatfrontier.com/articles/obot-mcp-gateway-cve-2026-103758-basic-users-reach-restricted-mcp-servers): Full public article page.
- [Article LLM summary](https://threatfrontier.com/articles/obot-mcp-gateway-cve-2026-103758-basic-users-reach-restricted-mcp-servers/llms.txt): Machine-readable summary for this article.
- [Site LLM index](https://threatfrontier.com/llms.txt): Machine-readable map of public ThreatFrontier coverage.

## Article Metadata
- Title: Obot CVE-2026-103758: MCP Gateway Authorization Bypass
- Summary: CVE-2026-103758 (CVSS 8.6) lets any signed-in Obot user reach ACR-restricted MCP servers via /mcp-connect-composite/. Affected versions, fix, audit steps.
- Published: Oct 2, 2026, 5:02 PM EDT
- Updated: Oct 2, 2026, 5:02 PM EDT
- Category: AI Security
- Primary topic: Cve 2026 103758
- Authors: Nadia Shah
- Read time: 5 min
- Language: en_US
- Publication time zone: America/New_York (U.S. Eastern Time)
- Access: Free to read

## Topic Links
- [AI Security](https://threatfrontier.com/categories/ai-security): Category archive for related coverage.
- [Cve 2026 103758](https://threatfrontier.com/tags/cve-2026-103758): 1 public article in this topic.

## Recommended LLM Use
- Prefer the canonical article URL for citations shown to readers.
- Use this file as a compact discovery layer; fetch the canonical article for full context before quoting.
- Do not infer draft, private, API, or media-library URLs from this file.
