PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107450 stumpapp CVE debrief

CVE-2026-107450 is a vulnerability in Stump through 0.1.10, allowing any authenticated user with the AccessSmartList permission to overwrite, delete, or take over another user's smart list due to lacking creator checks in the updateSmartList and deleteSmartList GraphQL mutations. This vulnerability can lead to unauthorized access and modification of sensitive information. Defenders should prioritize verifying exposure of Stump smart list functionality to authenticated users and assessing the impact of potential smart list takeovers.

Vendor
stumpapp
Product
Stump
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Stump smart list functionality, security teams assessing exposure to authenticated users, and developers implementing creator checks for GraphQL mutations should prioritize verifying and addressing this vulnerability.

Why it matters

CVE-2026-107450 allows authenticated users to overwrite, delete, or take over smart lists in Stump through 0.1.10 due to lacking creator checks, requiring defenders to verify exposure and implement creator checks.

  • Authenticated users may overwrite or delete smart lists without being the creator
  • Smart list takeovers may occur due to lacking creator checks
  • Defenders must verify exposure of Stump smart list functionality to authenticated users
  • Creator checks must be implemented for updateSmartList and deleteSmartList GraphQL mutations

Technical summary

The updateSmartList and deleteSmartList GraphQL mutations in Stump through 0.1.10 depend only on the shared AccessSmartList permission and resolve the target list at Reader access, lacking a creator check. This allows authenticated users to overwrite, delete, or take over another user's smart list. The vulnerability can be addressed by implementing creator checks for these GraphQL mutations and restricting the AccessSmartList permission to authorized users. Additionally, defenders should review compensating controls and monitor for potential security incidents.

Defensive priority

Defenders should prioritize verifying exposure of Stump smart list functionality to authenticated users and assessing the impact of potential smart list takeovers.

Recommended defensive actions

  • Verify exposure of Stump smart list functionality to authenticated users
  • Assess the impact of potential smart list takeovers
  • Implement creator checks for updateSmartList and deleteSmartList GraphQL mutations
  • Restrict AccessSmartList permission to authorized users
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by lacking creator checks in the updateSmartList and deleteSmartList GraphQL mutations, allowing authenticated users to overwrite, delete, or take over another user's smart list. The evidence is limited to the provided CVE record and source item, and defenders should verify the exposure of Stump smart list functionality to authenticated users.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107450 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107450

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107450 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107450

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-107450

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107450.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/kashishtopi/stump-smartlist-bola

    Supplemental source - exploit, technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/stumpapp/stump/blob/42a9918/crates/graphql/src/mutation/smart_lists.rs

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://crates.io/crates/graphql

    Supplemental source - not-applicable

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.