Description
stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious peer and gain access to or tamper with federation traffic. Fixed in 0.9.0a2, which introduces a pending approval flow requiring administrator fingerprint verification before peer tokens are accepted.
Published: 2026-08-19
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

stigmem-node version 0.9.0a1 allows an attacker to register a malicious federation peer because the application accepts federation peer key material without requiring an out‑of‑band administrator fingerprint verification step. This authentication bypass can be exploited by an adversary who controls or can intercept the initial registration traffic, enabling unauthorized peers to join the federation. Once registered, the attacker can read, modify, or delete federation traffic, compromising confidentiality, integrity, and continuity of federation communication.

Affected Systems

Vendors: Eidetic Labs’ stigmem. Affected product: stigmem-node. The vulnerability exists in release 0.9.0a1. The issue is resolved starting in 0.9.0a2, which introduces a pending approval flow that requires administrator fingerprint verification before accepting peer tokens.

Risk and Exploitability

CVSS score 9.1 indicates critical severity. EPSS score is not available; no listing in CISA KEV implies no public exploit campaigns are known yet. However, the vulnerability can be exploited remotely over the network during federation peer registration, requiring only the ability to send the registration request. Because the application lacks protected registration, the likelihood of exploitation in an open network is high. The absence of a blocked or mitigated entry in KEV and the lack of an EPSS indicator does not reduce the risk; organizations should consider any future discovery of active exploitation as a significant threat.

Generated by OpenCVE AI on August 19, 2026 at 18:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to stigmem-node 0.9.0a2 or later, which adds fingerprint verification before accepting peer tokens.
  • If an upgrade is not yet possible isolate federation registration traffic on a dedicated, monitored network segment and enforce strict firewall rules to prevent uncontrolled registration requests.
  • Enable logging and regularly review federation registration logs for unexpected or duplicate peer keys, and investigate any anomalies promptly.

Generated by OpenCVE AI on August 19, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious peer and gain access to or tamper with federation traffic. Fixed in 0.9.0a2, which introduces a pending approval flow requiring administrator fingerprint verification before peer tokens are accepted.
Title stigmem Federation Peer Registration Authentication Bypass
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-19T14:02:19.435Z

Reserved: 2026-08-19T11:38:33.225Z

Link: CVE-2026-76242

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:56.567

Modified: 2026-08-19T14:17:56.567

Link: CVE-2026-76242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T19:00:05Z

Weaknesses
  • CWE-295

    Improper Certificate Validation