PT-2026-78417 · Unknown+1 · Stigmem-Node+1

CVE-2026-76236

·

Published

2026-06-19

·

Updated

2026-08-21

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stigmem-node versions prior to 0.9.0a12
Description A broken object level authorization (BOLA) flaw exists in the right-to-be-forgotten (RTBF) tombstone mechanism. The issue tombstone function defaulted the tenant to "default" instead of the caller's tenant, which allowed deletion records to be written to the incorrect tenant. Additionally, the read-suppression path, specifically get tombstone filter and the tombstone scope cache, lacked a tenant id predicate, causing tombstone suppression to be applied without tenant differentiation across fact queries and provenance reads. This could result in a tenant's deletion being attributed to the wrong tenant, potentially hiding facts belonging to other tenants or failing to hide facts within the correct tenant, thereby undermining data isolation and RTBF guarantees. This issue only affects multi-tenant deployments using the opt-in stigmem-plugin-multi-tenant.
Recommendations Update stigmem-node to version 0.9.0a12.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76236
GHSA-X26H-XMV8-GXF7

Affected Products

Stigmem-Node
Stigmem-Plugin-Multi-Tenant