Broken Object Level Authorization in Stigmem by Eidetic Labs
CVE-2026-76238
7.2HIGH
What is CVE-2026-76238?
Stigmem versions prior to 0.9.0a12 are susceptible to a broken object level authorization flaw in the decay sweep endpoint. This vulnerability allows authenticated users with write access for a single tenant to execute decay operations that can inadvertently impact all tenants. Attackers can exploit this by sending POST requests to the decay sweep endpoint with parameters such as ttl_seconds=0, enabling them to expire critical data across all tenant environments. Additionally, using the dry_run parameter could give attackers access to sensitive information regarding fact counts and existence across tenants, posing a significant risk to data integrity and confidentiality.
Affected Version(s)
stigmem 0 < 0.9.0a12
stigmem 0.9.0a12
