Description
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.
Related CPE's
Could not find any relations
References
CVSS impact metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
4.2 · Medium
Information
Source identifier
Vulnerability status
Deferred
Published
2026-10-07T13:17:19.590Z
43 hours agoLast modified
2026-10-07T21:17:10.090Z
35 hours ago