CVE-2026-105140
Deferred Deferred - Pending Action

Race Condition in Obot Auth Provider Group Refreshes

Vulnerability report for CVE-2026-105140, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
obot-platform obot 0.25.0
obot-platform obot 0.26.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a race condition in the Obot platform (versions 0.25.0 to 0.25.5 and 0.26.0) where group memberships revoked in an identity provider can temporarily be restored. When multiple group refresh operations for the same user occur concurrently and commit out of order, stale membership data persists. This causes users to retain revoked group-based access for about ten minutes.

Detection Guidance

Monitor Obot logs for repeated group refresh failures or overlapping refresh operations for the same user. Check for instances where group memberships are restored after revocation. Review authentication provider logs for rate limiting or failed refresh attempts.

Impact Analysis

The impact is limited but could allow unauthorized access to resources for up to ten minutes after revocation. Users who should no longer have access to certain groups may temporarily retain that access. The vulnerability does not grant new access but delays the removal of existing permissions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements for data protection and access control. GDPR and HIPAA require timely revocation of access, and this delay may result in non-compliance. Immediate revocation of access is recommended to mitigate risks.

Mitigation Strategies
  • Upgrade Obot to version 0.25.6 or 0.26.1 or later to patch the race condition.
  • Manually revoke access for affected users in Obot until the upgrade is complete.
  • Monitor group refresh logs for overlapping operations and failed attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105140. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart