stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eidetic-labs
Eidetic-labs stigmem |
|
| Vendors & Products |
Eidetic-labs
Eidetic-labs stigmem |
Wed, 19 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments. | |
| Title | stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-19T14:02:20.160Z
Reserved: 2026-08-19T11:38:33.225Z
Link: CVE-2026-76243
No data.
Status : Received
Published: 2026-08-19T14:17:56.693
Modified: 2026-08-19T14:17:56.693
Link: CVE-2026-76243
No data.
OpenCVE Enrichment
Updated: 2026-08-20T16:30:04Z
Weaknesses