CVE-2026-105140

Source
https://cve.org/CVERecord?id=CVE-2026-105140
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105140.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105140
Aliases
  • GHSA-929v-v9hq-5xhr
Published
2026-10-07T12:18:33Z
Modified
2026-10-09T02:49:19Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership
Details

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-362"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105140.json"
}
References

Affected packages

Git / github.com/obot-platform/obot

Affected ranges

Type
GIT
Repo
https://github.com/obot-platform/obot
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.25.0"
        },
        {
            "fixed": "0.25.6"
        },
        {
            "introduced": "0.26.0"
        },
        {
            "fixed": "0.26.1"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.25.0
v0.25.1
v0.25.2
v0.25.3
v0.25.3-rc1
v0.25.3-rc2
v0.25.3-rc3
v0.25.4
v0.25.5
v0.25.5-rc1
v0.25.5-rc2
v0.25.5-rc3
v0.25.5-rc4
v0.25.5-rc5
v0.25.6-rc1
v0.26.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105140.json"