Race Condition in Obot Affects User Group Access
CVE-2026-105140
2.3LOW
What is CVE-2026-105140?
The Obot application versions prior to 0.25.6 and 0.26.1 exhibit a race condition that can lead to unintended restoration of group memberships that have been revoked in the identity provider. Specifically, when simultaneous refresh operations for a user occur out of order, outdated group memberships may be retained, enabling access for about ten minutes post-revocation. This vulnerability raises significant concerns for access control and user permissions, necessitating prompt updates to the affected versions to mitigate potential security risks.
Affected Version(s)
obot 0.25.0 < 0.25.6
obot 0.26.0 < 0.26.1
