PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76238 eidetic-labs CVE debrief

The CVE-2026-76238 record indicates a broken object level authorization vulnerability in stigmem versions before 0.9.0a12. This vulnerability exists in the decay sweep endpoint and allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tenants. The vulnerability can be exploited by submitting POST requests to the decay sweep endpoint with ttl_seconds=0 to expire facts across all tenants, or using dry_run to obtain cross-tenant fact counts and existence information. Users of stigmem should review and update to version 0.9.0a12 or later to mitigate this vulnerability.

Vendor
eidetic-labs
Product
stigmem-node
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-21
Advisory published
2026-08-19
Advisory updated
2026-08-21

Who should care

Users of stigmem versions before 0.9.0a12, administrators of systems with stigmem installed, security teams monitoring for vulnerabilities in stigmem, and operators responsible for maintaining tenant isolation and access controls should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing and updating stigmem to version 0.9.0a12 or later, restricting access to the decay sweep endpoint, and monitoring for suspicious POST requests to the decay sweep endpoint. Additionally, security teams should verify tenant isolation and access controls, and implement additional logging and monitoring for cross-tenant activity. Operators should also review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory and vulnerability management teams should also be aware of the potential impact of this vulnerability on their systems and take necessary actions to mitigate it. This may involve reviewing and updating asset inventories, and implementing additional monitoring and detection controls to identify and respond to potential exploitation attempts. By taking these actions, organizations can help protect their systems from the potential impact of this vulnerability and reduce the risk of exploitation. Security teams should also consider implementing rollback and change windows to ensure that any changes to the system are properly tested and validated before being deployed to production. Furthermore, source tracking and monitoring can help organizations detect and respond to potential exploitation attempts in a timely and effective manner. Overall, a comprehensive and multi-faceted approach is needed to fully mitigate the potential impact of this vulnerability and protect systems from exploitation. This includes a combination of technical, operational, and management controls, as well as ongoing monitoring and review to ensure that the vulnerability is properly mitigated and that systems are protected from exploitation. By taking a proactive and defense-in-depth approach, security,

Technical summary

CVE-2026-76238 is a broken object level authorization vulnerability in stigmem versions before 0.9.0a12. The vulnerability exists in the decay sweep endpoint and allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tenants. Attackers can submit POST requests to the decay sweep endpoint with ttl_seconds=0 to expire facts across all tenants, or use dry_run to obtain cross-tenant fact counts and existence information.

Defensive priority

Authenticated attackers with write credentials for one tenant can execute decay operations affecting all tenants, indicating a high priority for defense.

Recommended defensive actions

  • Review and update stigmem to version 0.9.0a12 or later
  • Restrict access to the decay sweep endpoint
  • Monitor for suspicious POST requests to the decay sweep endpoint
  • Implement additional logging and monitoring for cross-tenant activity
  • Verify tenant isolation and access controls

Evidence notes

The CVE-2026-76238 record indicates a broken object level authorization vulnerability in stigmem versions before 0.9.0a12. Authenticated attackers with write credentials for one tenant can execute decay operations affecting all tenants by submitting POST requests to the decay sweep endpoint with ttl_seconds=0 to expire facts across all tenants, or use dry_run to obtain cross-tenant fact counts and existence information. The vendor and product names are not specified, but Vulncheck is mentioned as a reference source.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:56.013Z and has not been modified since then.