CVE-2026-105140: low-severity vulnerability in obot-platform obot
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership
Published
5Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.3
exploitation probability
—
observed exploitation
nono source reports it
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
obot-platform · obotRelated CVEs — obot-platform obot
In the same product, most dangerous first.
CVE-2026-101065CRITICALObot Quickstart Docker Deployment Unauthenticated Admin AccessEPSS 0.4%CVE-2026-101062HIGHObot before v0.23.0 Authentication Bypass via OAuth Dynamic Client RegistrationEPSS 0.3%CVE-2026-101084CRITICALobot before v0.21.1 Authorization Bypass via /mcp-connectEPSS 0.3%CVE-2026-101063MEDIUMObot before v0.23.0 Authentication Bypass via Registry APIEPSS 0.2%CVE-2026-101064HIGHObot before v0.23.0 Server-Side Request Forgery via MCPEPSS 0.2%CVE-2026-103758HIGHObot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ RouteEPSS 0.2%
References
https://github.com/obot-platform/obothttps://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.go#L652-L734https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.go#L444-L456https://github.com/obot-platform/obot/blob/6f81dac8d344cf6b2161f500460fb7b2a975c415/pkg/gateway/client/group.go#L741-L757https://github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278https://github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415https://github.com/obot-platform/obot/releases/tag/v0.26.1https://github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhrhttps://www.vulncheck.com/advisories/obot-0.25.0-before-0.25.6-and-0.26.0-before-0.26.1-race-condition-restores-revoked-group-membership