CVE-2026-76243
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76243.json, https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-fp6w-8wpg-74g5, https://nvd.nist.gov/vuln/detail/CVE-2026-76243, https://www.vulncheck.com/advisories/stigmem-before-0a2-authentication-bypass-via-disabled-auth