Skip to content
Critical CVEs Disclosed for Rebuild and Obot Platforms

Critical CVEs Disclosed for Rebuild and Obot Platforms

First seen 29 Sep 2026, 11:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 11:09 UTC
  • •CVE-2026-102248 allows unauthenticated remote access in Rebuild.
  • •CVE-2026-101064 enables server-side request forgery in Obot.
  • •Public exploits are available for both vulnerabilities, increasing risk.

Two vulnerabilities have been disclosed affecting Rebuild and Obot platforms. CVE-2026-102248 in Rebuild versions up to 4.4.7/4.5.0-beta5 allows unauthenticated remote access to the login endpoint, posing a risk of account takeover. CVE-2026-101064 in Obot versions before v0.23.0 enables server-side request forgery, allowing privileged users to access internal services and sensitive credentials. The Rebuild vulnerability was published on 2026-09-29, while the Obot vulnerability was disclosed on 2026-09-27. Both vulnerabilities have public exploits available, increasing the urgency for affected organizations to take action. Organizations using these platforms should assess their exposure and implement mitigations immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-101064 published
Obot before v0.23.0 disclosed with a server-side request forgery vulnerability affecting privileged users.
Redpacketsecurity
2026-09-29
CVE-2026-102248 published
Rebuild up to versions 4.4.7/4.5.0-beta5 disclosed with an improper authentication vulnerability.
Redpacketsecurity

More articles in this cluster (4)

Following this threat?

Track CVE-2026-101064 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed