{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-105140", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-03T13:40:47.068Z", "datePublished": "2026-10-07T12:18:33.835Z", "dateUpdated": "2026-10-07T20:47:34.247Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-07T12:35:50.334Z" }, "datePublic": "2026-09-17T00:00:00.000Z", "title": "Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership", "descriptions": [ { "lang": "en", "value": "Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')", "cweId": "CWE-362", "type": "CWE" } ] } ], "affected": [ { "vendor": "obot-platform", "product": "obot", "defaultStatus": "unaffected", "packageURL": "pkg:golang/github.com/obot-platform/obot", "versions": [ { "version": "0.25.0", "lessThan": "0.25.6", "status": "affected", "versionType": "semver" }, { "version": "0.26.0", "lessThan": "0.26.1", "status": "affected", "versionType": "semver" } ] } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "HIGH", "attackRequirements": "PRESENT", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 2.3, "baseSeverity": "LOW" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 4.2, "baseSeverity": "MEDIUM" } } ], "references": [ { "url": "https://github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415", "tags": [ "patch" ], "name": "Patch Commit" }, { "url": "https://github.com/obot-platform/obot", "tags": [ "product" ] }, { "url": "https://github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhr", "tags": [ "vendor-advisory" ], "name": "GitHub Security Advisory (GHSA-929v-v9hq-5xhr)" }, { "url": "https://github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278", "tags": [ "patch" ] }, { "url": "https://github.com/obot-platform/obot/releases/tag/v0.26.1", "tags": [ "release-notes" ], "name": "obot v0.26.1 Release Notes" }, { "url": "https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.go#L652-L734", "tags": [ "technical-description" ] }, { "url": "https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.go#L444-L456", "tags": [ "technical-description" ] }, { "url": "https://github.com/obot-platform/obot/blob/6f81dac8d344cf6b2161f500460fb7b2a975c415/pkg/gateway/client/group.go#L741-L757", "tags": [ "technical-description" ] }, { "name": "VulnCheck Advisory: Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/obot-0.25.0-before-0.25.6-and-0.26.0-before-0.26.1-race-condition-restores-revoked-group-membership" } ], "credits": [ { "lang": "en", "value": "Scott Moore - VulnCheck", "type": "finder" } ], "x_generator": { "engine": "scooter" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T20:47:23.122671Z", "id": "CVE-2026-105140", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T20:47:34.247Z" } } ] } }