Obot MCP Gateway Flaw CVE-2026-103758 Lets Basic Users Reach Restricted MCP Servers
Obot 0.21.1–0.24.1 skips its ACR check on the composite MCP route, so any signed-in user can reach restricted servers. Obot says v0.25.0 fixes it.
· 5 minTracks IAM abuse, access governance, and authentication failure modes.
Obot 0.21.1–0.24.1 skips its ACR check on the composite MCP route, so any signed-in user can reach restricted servers. Obot says v0.25.0 fixes it.
· 5 minMicrosoft details Storm-3168: an Azure secret left in a GitHub issue led to 15.5 hours of recon, then a 7-minute run deleting storage and Key Vault.
· 4 minOpen WebUI 0.11.4 fixes 19 advisories, four high-severity and three of them session token theft. None has a CVE id. Upgrade and review sharing rights.
· 6 minZenity's SalesBleed used a public Web-to-Lead form and two URL-redaction bypasses to make Salesforce Agentforce leak CRM data over DNS.
· 3 min