CVE-2026-76243: Eidetic-Labs Stigmem

Critical severity, CVSS 9.2. EPSS: 0.6% chance of exploitation in the next 30 days.

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.

Affected products

Published 2026-08-19. Last modified 2026-09-24.