MEDIUM
stumpapp
CVE published 2026-10-08
CVE-2026-107450
CVE-2026-107450 is a vulnerability in Stump through 0.1.10, allowing any authenticated user with the AccessSmartList permission to overwrite, delete, or take over another user's smart list due to lacking creator checks in the updateSmartList and deleteSmartList GraphQL mutations. This vulnerability can lead to unauthorized access and modification of sensitive information. Defenders should prioritize verif [truncated]