PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76236 eidetic-labs CVE debrief

A cross-tenant broken object level authorization (BOLA) flaw was found in stigmem-node before version 0.9.0a12. The issue affects multi-tenant deployments using the stigmem-plugin-multi-tenant and allows a tenant's deletion to be attributed to the wrong tenant, undermining data isolation and right-to-be-forgotten (RTBF) guarantees. This vulnerability has a high CVSS score of 7.2 and is classified as HIGH severity. The flaw is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected.

Vendor
eidetic-labs
Product
stigmem-node
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-09-11
Advisory published
2026-08-19
Advisory updated
2026-09-11

Who should care

Defenders and administrators of multi-tenant deployments using stigmem-node should assess their exposure and prioritize remediation to prevent data isolation and RTBF guarantee compromises.

Why it matters

CVE-2026-76236 is a high-severity vulnerability affecting stigmem-node deployments. It allows cross-tenant BOLA attacks, compromising data isolation and RTBF guarantees. Defenders should prioritize verification and remediation, especially in multi-tenant environments.

  • Data isolation and RTBF guarantees may be compromised, allowing unauthorized data access or deletion.
  • Tenant data may be incorrectly attributed or suppressed, leading to data integrity issues.
  • Defenders should verify the stigmem-node version and assess deployment exposure to prevent potential data breaches.
  • Remediation priority is high for multi-tenant environments to prevent exploitation.

Technical summary

The stigmem-node before version 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF tombstone mechanism. This issue allows deletion records to be written to the wrong tenant and enables tenant-blind tombstone suppression across fact queries and provenance reads, affecting multi-tenant deployments using the stigmem-plugin-multi-tenant. The flaw is caused by the issue_tombstone defaulting the tenant to 'default' instead of the caller's tenant, and the read-suppression path lacking a tenant_id predicate.

Defensive priority

Defenders should prioritize verifying their deployment's exposure, especially in multi-tenant environments, and ensure the stigmem-node is updated to version 0.9.0a12 or later.

Recommended defensive actions

  • Verify if the stigmem-node version is 0.9.0a12 or later, especially in multi-tenant environments.
  • Assess the deployment's exposure to the vulnerability and prioritize remediation.
  • Monitor for any suspicious activity related to the RTBF mechanism and tenant data.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the affected versions. Vendor advisories and references offer additional context. The issue is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected. The CVE record was published on 2026-08-19T14:17:54.810Z and has not been modified since then. The NVD entry provides a detailed assessment of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76236 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76236

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76236 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76236

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.