PT-2026-78417 · Unknown+1 · Stigmem-Node+1
CVE-2026-76236
·
Published
2026-06-19
·
Updated
2026-08-21
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
stigmem-node versions prior to 0.9.0a12
Description
A broken object level authorization (BOLA) flaw exists in the right-to-be-forgotten (RTBF) tombstone mechanism. The
issue tombstone function defaulted the tenant to "default" instead of the caller's tenant, which allowed deletion records to be written to the incorrect tenant. Additionally, the read-suppression path, specifically get tombstone filter and the tombstone scope cache, lacked a tenant id predicate, causing tombstone suppression to be applied without tenant differentiation across fact queries and provenance reads. This could result in a tenant's deletion being attributed to the wrong tenant, potentially hiding facts belonging to other tenants or failing to hide facts within the correct tenant, thereby undermining data isolation and RTBF guarantees. This issue only affects multi-tenant deployments using the opt-in stigmem-plugin-multi-tenant.Recommendations
Update stigmem-node to version 0.9.0a12.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stigmem-Node
Stigmem-Plugin-Multi-Tenant