PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105140 obot-platform CVE debrief

CVE-2026-105140 is a low-severity vulnerability in Obot versions 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1. A race condition in auth provider group refreshes can restore revoked group memberships, allowing users to retain access for about ten minutes. Defenders should assess exposure, prioritize remediation, and verify affected systems. This vulnerability affects Obot deployments using auth provider group refreshes. The issue arises from overlapping refreshes for the same user committing out of order, which can persist stale memberships.

Vendor
obot-platform
Product
obot
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Obot deployments, particularly those using versions 0.25.0-0.25.5 and 0.26.0, should assess exposure and prioritize remediation. This includes verifying affected systems, applying patches, and reviewing auth provider group refresh configurations to prevent similar issues. Security teams and vulnerability management teams should also review the vulnerability and its potential impact on their environments.

Why it matters

CVE-2026-105140 is a low-severity vulnerability in Obot versions 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 that can restore revoked group memberships, allowing users to retain access for about ten minutes. Defenders should assess exposure, prioritize remediation, and verify affected systems.

  • Verify affected Obot versions to prevent potential access restoration
  • Apply patches to prevent potential access restoration
  • Review auth provider group refresh configurations to prevent similar issues

Technical summary

A race condition in Obot's auth provider group refreshes can restore revoked group memberships, allowing users to retain access for about ten minutes. This occurs when overlapping refreshes for the same user commit out of order, persisting stale memberships. The vulnerability affects Obot versions 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1. Defenders should prioritize verifying affected Obot versions and applying patches to prevent potential access restoration. The issue is specific to auth provider group refreshes and does not affect other Obot functionality.

Defensive priority

Defenders should prioritize verifying affected Obot versions and applying patches to prevent potential access restoration.

Recommended defensive actions

  • Verify Obot versions 0.25.0-0.25.5 and 0.26.0 in use and apply patches
  • Review auth provider group refresh configurations
  • Monitor for potential access restoration
  • Apply patches to prevent potential access restoration
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and patch commits. The vulnerability has been patched in Obot versions 0.25.6 and 0.26.1. Defenders should verify affected systems and apply patches to prevent potential access restoration. The source item and CVE record provide further information on the vulnerability and affected scope.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105140 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105140

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105140 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105140

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Members

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105140.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/obot-platform/obot

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhr

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/obot-platform/obot/releases/tag/v0.26.1

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.go

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.go

    Supplemental source - technical-description

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.