stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 19 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments. | |
| Title | stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-19T14:02:20.160Z
Reserved: 2026-08-19T11:38:33.225Z
Link: CVE-2026-76243
No data.
Status : Received
Published: 2026-08-19T14:17:56.693
Modified: 2026-08-19T14:17:56.693
Link: CVE-2026-76243
No data.
OpenCVE Enrichment
No data.
Weaknesses