PT-2026-78424 · Stigmem · Stigmem
CVE-2026-76243
·
Published
2026-05-29
·
Updated
2026-08-25
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
stigmem versions prior to 0.9.0a2
Description
An authentication bypass occurs when authentication is disabled on non-loopback deployments. This allows attackers to perform read, write, and federation operations using an anonymous identity when nodes are exposed outside of local development environments.
Recommendations
Update stigmem to version 0.9.0a2 or later.
Exploit
Fix
Missing Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stigmem