PatchSiren cyber security CVE debrief
CVE-2026-76236 eidetic-labs CVE debrief
A cross-tenant broken object level authorization (BOLA) flaw was found in stigmem-node before version 0.9.0a12. The issue affects multi-tenant deployments using the stigmem-plugin-multi-tenant and allows a tenant's deletion to be attributed to the wrong tenant, undermining data isolation and right-to-be-forgotten (RTBF) guarantees. This vulnerability has a high CVSS score of 7.2 and is classified as HIGH severity. The flaw is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected.
- Vendor
- eidetic-labs
- Product
- stigmem-node
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-11
Who should care
Defenders and administrators of multi-tenant deployments using stigmem-node should assess their exposure and prioritize remediation to prevent data isolation and RTBF guarantee compromises.
Why it matters
CVE-2026-76236 is a high-severity vulnerability affecting stigmem-node deployments. It allows cross-tenant BOLA attacks, compromising data isolation and RTBF guarantees. Defenders should prioritize verification and remediation, especially in multi-tenant environments.
- Data isolation and RTBF guarantees may be compromised, allowing unauthorized data access or deletion.
- Tenant data may be incorrectly attributed or suppressed, leading to data integrity issues.
- Defenders should verify the stigmem-node version and assess deployment exposure to prevent potential data breaches.
- Remediation priority is high for multi-tenant environments to prevent exploitation.
Technical summary
The stigmem-node before version 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF tombstone mechanism. This issue allows deletion records to be written to the wrong tenant and enables tenant-blind tombstone suppression across fact queries and provenance reads, affecting multi-tenant deployments using the stigmem-plugin-multi-tenant. The flaw is caused by the issue_tombstone defaulting the tenant to 'default' instead of the caller's tenant, and the read-suppression path lacking a tenant_id predicate.
Defensive priority
Defenders should prioritize verifying their deployment's exposure, especially in multi-tenant environments, and ensure the stigmem-node is updated to version 0.9.0a12 or later.
Recommended defensive actions
- Verify if the stigmem-node version is 0.9.0a12 or later, especially in multi-tenant environments.
- Assess the deployment's exposure to the vulnerability and prioritize remediation.
- Monitor for any suspicious activity related to the RTBF mechanism and tenant data.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the affected versions. Vendor advisories and references offer additional context. The issue is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected. The CVE record was published on 2026-08-19T14:17:54.810Z and has not been modified since then. The NVD entry provides a detailed assessment of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76236 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76236
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76236 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76236
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-x26h-xmv8-gxf7
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/stigmem-before-0a12-cross-tenant-bola-via-tombstones
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.