Description
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, allowing deletion records to be written to the wrong tenant, and the read-suppression path (_get_tombstone_filter and the tombstone scope cache) lacked a tenant_id predicate, so tombstone suppression was applied tenant-blind across fact queries and provenance reads. As a result, a tenant's deletion could be attributed to the wrong tenant and tombstone suppression could either hide facts belonging to other tenants or fail to hide facts within the correct tenant, undermining data isolation and RTBF guarantees. The issue is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected. Fixed in 0.9.0a12.
Published: 2026-08-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the right‑to‑be‑forgotten tombstone routine of stigmem-node. During deletion a flag that records the tenant was incorrectly defaulted to "default" with the entry written to that tenant. The deletion filter for tombstone suppression then omitted a tenant identifier, so tombstones were applied across all tenants. This allows a user of one tenant to cause facts belonging to another tenant to be deleted or to elude deletion, thereby breaching data isolation and violating RTBF guarantees.

Affected Systems

Eidetic‑Labs stigmem-node versions earlier than 0.9.0a12 that use the optional stigmem‑plugin‑multi‑tenant. Single‑tenant deployments are not impacted.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium‑high severity. The EPSS score is < 1%, showing a very low probability of exploitation observed in the wild, and the vulnerability is not listed in CISA KEV. Exploitation requires a multi‑tenant deployment and a legitimate account with deletion privileges. An attacker can create tombstone records that delete or hide data belonging to other tenants, thereby breaching data isolation and violating RTBF guarantees. The attack can be carried out by submitting a deletion request and then querying data that would normally be suppressed. Given the lack of external exposure, the risk is limited to environments where the multi‑tenant plugin is enabled.

Generated by OpenCVE AI on August 20, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade stigmem-node to version 0.9.0a12 or newer
  • Disable the stigmem‑plugin‑multi‑tenant if multi‑tenant support is not required
  • Review tenant‑aware configuration to ensure deletions and tombstone filters include correct tenant predicates

Generated by OpenCVE AI on August 20, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Eidetic-labs
Eidetic-labs stigmem
Vendors & Products Eidetic-labs
Eidetic-labs stigmem

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, allowing deletion records to be written to the wrong tenant, and the read-suppression path (_get_tombstone_filter and the tombstone scope cache) lacked a tenant_id predicate, so tombstone suppression was applied tenant-blind across fact queries and provenance reads. As a result, a tenant's deletion could be attributed to the wrong tenant and tombstone suppression could either hide facts belonging to other tenants or fail to hide facts within the correct tenant, undermining data isolation and RTBF guarantees. The issue is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected. Fixed in 0.9.0a12.
Title stigmem before 0.9.0a12 Cross-Tenant BOLA via Tombstones
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Eidetic-labs Stigmem
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-21T19:51:02.809Z

Reserved: 2026-08-19T11:38:33.224Z

Link: CVE-2026-76236

cve-icon Vulnrichment

Updated: 2026-08-21T19:50:56.877Z

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:54.810

Modified: 2026-08-21T20:16:44.087

Link: CVE-2026-76236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:15:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key