CVE-2026-76243

Summary

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.

Affected Software

VendorProductVersion RangeStatus
eidetic-labsstigmem0 < 0.9.0a2affected
eidetic-labsstigmem0.9.0a2unaffected

Weaknesses

  • CWE-285: Improper Authorization

References