Authentication Bypass in Stigmem by Eidetic Labs
CVE-2026-76243

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76243?

Versions of Stigmem prior to 0.9.0a2 are susceptible to an authentication bypass vulnerability that enables unauthenticated users to gain access. When authentication is disabled, particularly in non-loopback deployments, attackers can exploit this flaw to perform read, write, and federation actions using anonymous identities. This becomes especially critical when nodes are inadvertently exposed outside of local development environments, allowing potential misuse in production settings.

Affected Version(s)

stigmem 0 < 0.9.0a2

stigmem 0.9.0a2

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.