Cross-Tenant Authorization Flaw in Stigmem Node by Eidetic Labs
CVE-2026-76236

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76236?

The stigmem-node prior to version 0.9.0a12 contains a critical vulnerability in its right-to-be-forgotten (RTBF) tombstone mechanism due to a cross-tenant broken object level authorization (BOLA) flaw. The issue arises because the tombstone is set to the 'default' tenant rather than the caller's tenant, leading to incorrect deletion records being written. Additionally, the mechanisms in place for tombstone suppression lack adequate tenant-based restrictions, enabling unauthorized access to deletion records and undermining data isolation. This vulnerability primarily affects multi-tenant deployments that utilize the stigmem-plugin-multi-tenant; those operating under a single-tenant configuration remain unaffected. A fix has been introduced in version 0.9.0a12.

Affected Version(s)

stigmem 0 < 0.9.0a12

stigmem 0.9.0a12

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.