CVE-2026-76238
stigmem before 0.9.0a12 Cross-Tenant BOLA via decay sweep
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tenants. Attackers can submit POST requests to the decay sweep endpoint with ttl_seconds=0 to expire facts across all tenants, or use dry_run to obtain cross-tenant fact counts and existence information.
| CWE | CWE-863 |
| Vendor | eidetic-labs |
| Product | stigmem |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for eidetic-labs stigmem
Be the first to know when new unknown vulnerabilities affecting eidetic-labs stigmem are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
eidetic-labs / stigmem
0 < 0.9.0a12