PT-2026-78419 · Stigmem · Stigmem
CVE-2026-76238
·
Published
2026-06-19
·
Updated
2026-08-25
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
stigmem versions prior to 0.9.0a12
Description
An issue exists in the decay sweep endpoint where broken object level authorization allows authenticated attackers with write credentials for a single tenant to perform decay operations across all tenants. By submitting POST requests to the decay sweep endpoint, attackers can use the
ttl seconds variable set to 0 to expire facts for all tenants or utilize the dry run variable to retrieve cross-tenant fact counts and existence information.Recommendations
Update stigmem to version 0.9.0a12 or later.
Restrict access to the decay sweep endpoint to minimize the risk of unauthorized cross-tenant operations.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stigmem