{"id":"CVE-2026-105140","title":"Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider","summary":"Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit o…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-362"],"vendor":"obot-platform","product":"obot","affected":["obot >= 0.25.0 < 0.25.6","obot >= 0.26.0 < 0.26.1"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T13:17:19.733","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105140","references":[{"url":"https://github.com/obot-platform/obot","label":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.go#L652-L734","label":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.go#L444-L456","label":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/6f81dac8d344cf6b2161f500460fb7b2a975c415/pkg/gateway/client/group.go#L741-L757","label":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278","label":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415","label":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/releases/tag/v0.26.1","label":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhr","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/obot-0.25.0-before-0.25.6-and-0.26.0-before-0.26.1-race-condition-restores-revoked-group-membership","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T13:31:04.596Z","slug":"CVE-2026-105140","body":"## Overview\n\nObot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}