CVE-2026-76238

Source
https://cve.org/CVERecord?id=CVE-2026-76238
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76238.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76238
Aliases
Published
2026-08-19T14:02:16.612Z
Modified
2026-08-23T03:42:52.420615799Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
stigmem before 0.9.0a12 Cross-Tenant BOLA via decay sweep
Details

stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tenants. Attackers can submit POST requests to the decay sweep endpoint with ttlseconds=0 to expire facts across all tenants, or use dryrun to obtain cross-tenant fact counts and existence information.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76238.json"
}
References

Affected packages

Git / github.com/eidetic-labs/stigmem

Affected ranges

Type
GIT
Repo
https://github.com/eidetic-labs/stigmem
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.9.0a12"
        }
    ]
}

Affected versions

v0.*
v0.9.0a10
v0.9.0a11
v0.9.0a2
v0.9.0a3
v0.9.0a4
v0.9.0a5
v0.9.0a6
v0.9.0a7
v0.9.0a8
v0.9.0a9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76238.json"