Medium severity4.2NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-105140
CVE-2026-105140
Description
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.
Affected products
1- Range: 0.25.0 <= 0.25.6, 0.26.0 < 0.26.1
Patches
Vulnerability mechanics
References
8- github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.gonvd
- github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.gonvd
- github.com/obot-platform/obot/blob/6f81dac8d344cf6b2161f500460fb7b2a975c415/pkg/gateway/client/group.gonvd
- github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278nvd
- github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415nvd
- github.com/obot-platform/obot/releases/tag/v0.26.1nvd
- github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhrnvd
- www.vulncheck.com/advisories/obot-0.25.0-before-0.25.6-and-0.26.0-before-0.26.1-race-condition-restores-revoked-group-membershipnvd
News mentions
0No linked articles in our index yet.