Description


Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.

Related CPE's


Could not find any relations

Weaknesses



CWE-362

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

4.2 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-07T13:17:19.590Z

43 hours ago

Last modified

2026-10-07T21:17:10.090Z

35 hours ago