VYPR
Medium severity4.2NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026

CVE-2026-105140

CVE-2026-105140

Description

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.

Affected products

1

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.