Back

HIGH

stigmem before 0.9.0a12 Cross-Tenant BOLA via quarantine

Published Aug 19, 2026

Description

stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count queries and _get_quarantined_fact in routes/quarantine.py lacked a tenant_id predicate and the garden lookup was not tenant-scoped, allowing a tenant administrator with only a plain tenant write capability to list, read, and admit or reject quarantined facts belonging to other tenants via the /v1/quarantine endpoints. Default single-tenant deployments are not affected.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 21, 2026
Reserved Aug 19, 2026
CISA Vulnrichment
Updated Aug 20, 2026
NVD
Status Received
Modified Aug 21, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 21, 2026
Exploited since n/a
EUVD-2026-62477