Impact
The vulnerability is a race condition in the auth provider group refresh logic. When two concurrent refresh operations for the same user complete out of order, outdated group information is persisted, allowing a user to retain group memberships that have been revoked remotely, providing unauthorized access for approximately ten minutes.
Affected Systems
The issue affects obot-platform's obot product versions 0.25.0 through 0.25.5 and 0.26.0. The fixed releases are 0.25.6 and 0.26.1.
Risk and Exploitability
The CVSS score is 2.3, indicating a low severity. EPSS is not available and the vulnerability is not listed in CISA KEV. Exploitation requires concurrent group refreshes for the same user, so the attack vector is internal or requires elevated permissions to trigger overlapping requests. The impact window is about ten minutes, limiting the overall risk but still allowing malicious users to maintain revoked privileges temporarily.
OpenCVE Enrichment