PatchSiren cyber security CVE debrief
CVE-2026-105140 obot-platform CVE debrief
CVE-2026-105140 is a low-severity vulnerability in Obot versions 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1. A race condition in auth provider group refreshes can restore revoked group memberships, allowing users to retain access for about ten minutes. Defenders should assess exposure, prioritize remediation, and verify affected systems. This vulnerability affects Obot deployments using auth provider group refreshes. The issue arises from overlapping refreshes for the same user committing out of order, which can persist stale memberships.
- Vendor
- obot-platform
- Product
- obot
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Obot deployments, particularly those using versions 0.25.0-0.25.5 and 0.26.0, should assess exposure and prioritize remediation. This includes verifying affected systems, applying patches, and reviewing auth provider group refresh configurations to prevent similar issues. Security teams and vulnerability management teams should also review the vulnerability and its potential impact on their environments.
Why it matters
CVE-2026-105140 is a low-severity vulnerability in Obot versions 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 that can restore revoked group memberships, allowing users to retain access for about ten minutes. Defenders should assess exposure, prioritize remediation, and verify affected systems.
- Verify affected Obot versions to prevent potential access restoration
- Apply patches to prevent potential access restoration
- Review auth provider group refresh configurations to prevent similar issues
Technical summary
A race condition in Obot's auth provider group refreshes can restore revoked group memberships, allowing users to retain access for about ten minutes. This occurs when overlapping refreshes for the same user commit out of order, persisting stale memberships. The vulnerability affects Obot versions 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1. Defenders should prioritize verifying affected Obot versions and applying patches to prevent potential access restoration. The issue is specific to auth provider group refreshes and does not affect other Obot functionality.
Defensive priority
Defenders should prioritize verifying affected Obot versions and applying patches to prevent potential access restoration.
Recommended defensive actions
- Verify Obot versions 0.25.0-0.25.5 and 0.26.0 in use and apply patches
- Review auth provider group refresh configurations
- Monitor for potential access restoration
- Apply patches to prevent potential access restoration
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and patch commits. The vulnerability has been patched in Obot versions 0.25.6 and 0.26.1. Defenders should verify affected systems and apply patches to prevent potential access restoration. The source item and CVE record provide further information on the vulnerability and affected scope.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105140 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105140
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105140 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105140
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Members
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105140.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/obot-platform/obot
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhr
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/obot-platform/obot/releases/tag/v0.26.1
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.go
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.go
Supplemental source - technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.