Description
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
Published: 2026-08-19
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Versions of the stigmem application prior to 0.9.0a2 permit unauthenticated access when the authentication feature is disabled. This flaw allows an attacker to perform arbitrary read, write, and federation operations with the same privileges as an anonymous user, effectively providing full control over all exposed resources. The underlying weakness is a lack of access control when authentication is disabled, classified as CWE‑285.

Affected Systems

The vulnerability affects all installations of eidetic‑labs' stigmem up to and including versions earlier than 0.9.0a2. Any deployment that has disabled authentication and is reachable from outside the localhost namespace is susceptible. No specific sub‑versions are listed beyond the overall cutoff of 0.9.0a2.

Risk and Exploitability

The CVSS score of 9.2 indicates a high severity level. The EPSS score for this vulnerability is less than 1%, indicating a low probability of exploitation. The vulnerability does not appear in the CISA KEV catalog. Based on the description, the likely attack vector is remotely accessing the application over a network when authentication is turned off, allowing an attacker to execute any operation permitted to an anonymous session.

Generated by OpenCVE AI on August 20, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade stigmem to version 0.9.0a2 or later, which restores authentication checks and prevents anonymous access when authentication is disabled.
  • Ensure that any nodes or instances where authentication is disabled are not exposed to external networks; restrict access to the localhost or internal network only.
  • Configure network perimeter controls or firewall rules to block HTTP traffic to the stigmem service from untrusted sources until authentication is re‑enabled.

Generated by OpenCVE AI on August 20, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Eidetic-labs
Eidetic-labs stigmem
Vendors & Products Eidetic-labs
Eidetic-labs stigmem

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
Title stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Eidetic-labs Stigmem
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-25T02:01:37.954Z

Reserved: 2026-08-19T11:38:33.225Z

Link: CVE-2026-76243

cve-icon Vulnrichment

Updated: 2026-08-25T02:01:34.309Z

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:56.693

Modified: 2026-08-25T03:16:58.617

Link: CVE-2026-76243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T16:30:04Z

Weaknesses