Broken Object Level Authorization in Stigmem by Eidetic Labs
CVE-2026-76238

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76238?

Stigmem versions prior to 0.9.0a12 are susceptible to a broken object level authorization flaw in the decay sweep endpoint. This vulnerability allows authenticated users with write access for a single tenant to execute decay operations that can inadvertently impact all tenants. Attackers can exploit this by sending POST requests to the decay sweep endpoint with parameters such as ttl_seconds=0, enabling them to expire critical data across all tenant environments. Additionally, using the dry_run parameter could give attackers access to sensitive information regarding fact counts and existence across tenants, posing a significant risk to data integrity and confidentiality.

Affected Version(s)

stigmem 0 < 0.9.0a12

stigmem 0.9.0a12

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.