CRITICAL 9.4 CVE-2026-54618 Published 17 Sept 2026

Obsidian Web MCP Unauthenticated Access Vulnerability

Worried this affects your website?

Obsidian Web MCP, a secure remote MCP server for Obsidian vaults, was affected by an unauthenticated access vulnerability prior to version 0.2.0.

Obsidian Web MCP failed to perform login, consent, or session checks for the /oauth/authorize endpoint, allowing an attacker to obtain an authorization code. Additionally, the /oauth/token endpoint could exchange this code for the static VAULT_MCP_TOKEN without authenticating a client.

This vulnerability allowed unauthenticated remote callers to perform various operations against the entire vault, including vault_read, vault_write, vault_search, vault_list, vault_move, and vault_delete. Optional PKCE did not prevent an attacker-initiated flow, and unauthenticated /oauth/register exposed the configured VAULT_OAUTH_CLIENT_SECRET.

Reference: CVE-2026-54618 on NVD

← Back to Security News