SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76244

CRITICAL · CVSS 9.1 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in stigmem-node arises from an insecure default configuration that permits federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. This oversight can lead to cleartext interception and man-in-the-middle attacks, posing a significant risk to data integrity and confidentiality. Organizations utilizing stigmem-node should prioritize remediation, especially those with exposed federation traffic configurations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76244
Severity
CRITICAL
CVSS
9.1
EPSS
0.22%

Original NVD Description

stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks.