CVE-2026-105140: Obot-Platform Obot
Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.
Affected products
- Obot-Platform Obot: from 0.25.0, before 0.25.6 (fixed in 0.25.6); from 0.26.0, before 0.26.1 (fixed in 0.26.1)
Published 2026-10-07. Last modified 2026-10-07.