SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76243

CRITICAL · CVSS 9.2 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Versions of stigmem prior to 0.9.0a2 are critically vulnerable due to unauthenticated access being permitted when authentication is disabled on non-loopback deployments. This flaw allows attackers to execute read, write, and federation operations with an anonymous identity, posing significant risks if nodes are exposed beyond local development environments. Organizations using stigmem should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76243
Severity
CRITICAL
CVSS
9.2
EPSS
0.40%

Original NVD Description

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.