CVE-2026-105140

CVE-2026-105140 published: Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale m...

View full NVD advisory → ← Back to CVE watch