OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-54618

CRITICAL · CVSS 9.4 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects Obsidian Web MCP prior to version 0.2.0, allowing unauthenticated remote attackers to exploit the OAuth authorization process, granting them unauthorized access to sensitive vault operations such as read, write, and delete. The lack of proper authentication checks poses a critical risk, enabling attackers to manipulate vault contents without any user consent or session verification. Organizations using affected versions of Obsidian Web MCP should prioritize upgrading to version 0.2.0 to mitigate this severe security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54618
Severity
CRITICAL
CVSS
9.4
EPSS
0.51%
Exchange

Original NVD Description

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client. An unauthenticated remote caller who can reach the intended tunnel deployment can therefore call /mcp and use vault_read, vault_write, vault_search, vault_list, vault_move, and vault_delete against the entire vault. Optional PKCE does not prevent an attacker-initiated flow, and unauthenticated /oauth/register also exposes a client_credentials path by returning the configured VAULT_OAUTH_CLIENT_SECRET. This issue is fixed in version 0.2.0.