PatchSiren cyber security CVE debrief
CVE-2026-107450 stumpapp CVE debrief
CVE-2026-107450 is a vulnerability in Stump through 0.1.10, allowing any authenticated user with the AccessSmartList permission to overwrite, delete, or take over another user's smart list due to lacking creator checks in the updateSmartList and deleteSmartList GraphQL mutations. This vulnerability can lead to unauthorized access and modification of sensitive information. Defenders should prioritize verifying exposure of Stump smart list functionality to authenticated users and assessing the impact of potential smart list takeovers.
- Vendor
- stumpapp
- Product
- Stump
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Stump smart list functionality, security teams assessing exposure to authenticated users, and developers implementing creator checks for GraphQL mutations should prioritize verifying and addressing this vulnerability.
Why it matters
CVE-2026-107450 allows authenticated users to overwrite, delete, or take over smart lists in Stump through 0.1.10 due to lacking creator checks, requiring defenders to verify exposure and implement creator checks.
- Authenticated users may overwrite or delete smart lists without being the creator
- Smart list takeovers may occur due to lacking creator checks
- Defenders must verify exposure of Stump smart list functionality to authenticated users
- Creator checks must be implemented for updateSmartList and deleteSmartList GraphQL mutations
Technical summary
The updateSmartList and deleteSmartList GraphQL mutations in Stump through 0.1.10 depend only on the shared AccessSmartList permission and resolve the target list at Reader access, lacking a creator check. This allows authenticated users to overwrite, delete, or take over another user's smart list. The vulnerability can be addressed by implementing creator checks for these GraphQL mutations and restricting the AccessSmartList permission to authorized users. Additionally, defenders should review compensating controls and monitor for potential security incidents.
Defensive priority
Defenders should prioritize verifying exposure of Stump smart list functionality to authenticated users and assessing the impact of potential smart list takeovers.
Recommended defensive actions
- Verify exposure of Stump smart list functionality to authenticated users
- Assess the impact of potential smart list takeovers
- Implement creator checks for updateSmartList and deleteSmartList GraphQL mutations
- Restrict AccessSmartList permission to authorized users
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by lacking creator checks in the updateSmartList and deleteSmartList GraphQL mutations, allowing authenticated users to overwrite, delete, or take over another user's smart list. The evidence is limited to the provided CVE record and source item, and defenders should verify the exposure of Stump smart list functionality to authenticated users.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107450 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107450
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107450 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107450
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-107450
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107450.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/kashishtopi/stump-smartlist-bola
Supplemental source - exploit, technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/stumpapp/stump/blob/42a9918/crates/graphql/src/mutation/smart_lists.rs
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://crates.io/crates/graphql
Supplemental source - not-applicable
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.