Cross-Tenant Authorization Flaw in Stigmem Node by Eidetic Labs
CVE-2026-76236
What is CVE-2026-76236?
The stigmem-node prior to version 0.9.0a12 contains a critical vulnerability in its right-to-be-forgotten (RTBF) tombstone mechanism due to a cross-tenant broken object level authorization (BOLA) flaw. The issue arises because the tombstone is set to the 'default' tenant rather than the caller's tenant, leading to incorrect deletion records being written. Additionally, the mechanisms in place for tombstone suppression lack adequate tenant-based restrictions, enabling unauthorized access to deletion records and undermining data isolation. This vulnerability primarily affects multi-tenant deployments that utilize the stigmem-plugin-multi-tenant; those operating under a single-tenant configuration remain unaffected. A fix has been introduced in version 0.9.0a12.
Affected Version(s)
stigmem 0 < 0.9.0a12
stigmem 0.9.0a12
