---
id: CVE-2026-105140
title: >-
  Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition
  in auth provider group refreshes that can restore group memberships just
  revoked in the identity provider
summary: >-
  Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition
  in auth provider group refreshes that can restore group memberships just
  revoked in the identity provider. When overlapping refreshes for the same user
  commit o…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-362
vendor: obot-platform
product: obot
affected:
  - obot >= 0.25.0 < 0.25.6
  - obot >= 0.26.0 < 0.26.1
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:17:19.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105140'
references:
  - url: 'https://github.com/obot-platform/obot'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.go#L652-L734
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.go#L444-L456
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/blob/6f81dac8d344cf6b2161f500460fb7b2a975c415/pkg/gateway/client/group.go#L741-L757
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415
    label: disclosure@vulncheck.com
  - url: 'https://github.com/obot-platform/obot/releases/tag/v0.26.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhr
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/obot-0.25.0-before-0.25.6-and-0.26.0-before-0.26.1-race-condition-restores-revoked-group-membership
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T13:31:04.596Z'
---

## Overview

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
