Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-76243: stigmem-node: Anonymous access risk when auth is disabled outside loopback

CVE-2026-76243 · published 15 days ago
Summary

Operators who intentionally disabled authentication in stigmem-node may inadvertently grant broad access to anonymous users if the node is exposed outside a local development environment. To avoid this, keep authentication enabled for all non-local deployments. Upgrade to the latest version of stigmem-node to ensure this security fix is applied.

What to do
  • Update stigmem-node to version 0.9.0a2.
  • Update eidetic-labs stigmem to version 0.9.0a2 or later.
Affected software
Ecosystem VendorProductAffected versions
pip stigmem-node < 0.9.0a2
Fix: upgrade to 0.9.0a2
eidetic-labs stigmem < 0.9.0a2
Original advisory text
stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
Severity
9.9 Critical
CVSS 4.0: 9.2 (GHSA)
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-285Improper Authorization
CWE-862Missing Authorization
Timeline
Published19 Aug 2026
Updated3 Sep 2026
First seen29 May 2026
Sources
CVE-2026-76243 · MITRE
Monitor software like this
Free during beta