PT-2026-78419 · Stigmem · Stigmem

CVE-2026-76238

·

Published

2026-06-19

·

Updated

2026-08-25

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stigmem versions prior to 0.9.0a12
Description An issue exists in the decay sweep endpoint where broken object level authorization allows authenticated attackers with write credentials for a single tenant to perform decay operations across all tenants. By submitting POST requests to the decay sweep endpoint, attackers can use the ttl seconds variable set to 0 to expire facts for all tenants or utilize the dry run variable to retrieve cross-tenant fact counts and existence information.
Recommendations Update stigmem to version 0.9.0a12 or later. Restrict access to the decay sweep endpoint to minimize the risk of unauthorized cross-tenant operations.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76238
GHSA-6GQW-JQV7-V88M

Affected Products

Stigmem