Sceawere

Vulnerability Detail

CVE-2026-107450UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stump Broken Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
stumpapp
Product
Stump
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

In Stump through 0.1.10, the updateSmartList and deleteSmartList GraphQL mutations (crates/graphql/src/mutation/smart_lists.rs) depend only on the shared AccessSmartList permission and resolve the target list at Reader access (lacking a creator check). Any authenticated user with that permission can overwrite, delete, or take over another user's smart list. (updateSmartList sets creatorId to the caller identity, and can set visibility to PRIVATE, locking out the original owner.) NOTE: this is unrelated to the graphql crate on crates.io.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-08T05:17:04.477Z",
  "pubdate": "2026-10-08T05:17:04.477Z",
  "executiveSummary": "Stump versions through 0.1.10 are susceptible to a critical broken access control vulnerability within its GraphQL API implementation.\nThe vulnerability originates from inadequate authorization checks during the processing of smart list mutations.\nSpecifically, the 'updateSmartList' and 'deleteSmartList' operations fail to verify ownership, allowing any authenticated user possessing the 'AccessSmartList' permission to manipulate or destroy smart lists created by other users.\nThis flaw enables unauthorized data modification, account takeover of list resources, and persistent denial-of-service through deletion.\nBy manipulating the 'creatorId' and visibility settings, an attacker can effectively hijack smart lists, restricting access to the original owner and assuming control over the targeted data assets.\nThis constitutes a high-risk security defect as it bypasses intended logical boundaries within the application's multi-user environment.\nExploitation requires active authentication but does not require administrative privileges, making it accessible to any standard authenticated user within the system.",
  "technicalDetails": "The vulnerability resides in the GraphQL mutation resolvers defined in 'crates/graphql/src/mutation/smart_lists.rs'.\nThe root cause is a deficiency in the authorization logic applied to the 'updateSmartList' and 'deleteSmartList' GraphQL mutations. While the application enforces a generic 'AccessSmartList' permission, the backend logic fails to validate that the user performing the operation is the legitimate owner (creator) of the targeted smart list resource.\nThe resolution process defaults to a 'Reader' access level context, which is insufficient for preventing unauthorized mutations on objects belonging to other users.\nWhen an attacker triggers the 'updateSmartList' mutation, the application allows the modification of list attributes without validating resource ownership. Crucially, the mutation logic updates the 'creatorId' attribute to the current requester's identity. Furthermore, an attacker can modify the 'visibility' parameter to 'PRIVATE', effectively locking out the original owner from their own resource and granting exclusive control to the attacker.\nThe attack flow proceeds as follows: 1) An authenticated attacker identifies the target smart list ID. 2) The attacker issues a crafted GraphQL request targeting 'updateSmartList' or 'deleteSmartList' referencing the victim's smart list ID. 3) The backend, evaluating only the shared 'AccessSmartList' permission, authorizes the request. 4) The application executes the mutation, updating the 'creatorId' to the attacker's ID or removing the resource entirely from the database.\nBecause these mutations operate on the server-side state without enforcing ownership-based identity checks, the integrity and confidentiality of user-specific data are compromised. The scope of the impact includes unauthorized data exfiltration, permanent deletion of legitimate user content, and persistent privilege escalation over specific application entities.\nThe vulnerability affects all identified versions up to 0.1.10. It is important to note that this issue is isolated to the Stump application logic and is not related to any third-party crates found on crates.io."
}
CVE-2026-107450: Stump Broken Access Control (MEDIUM Severity, CVSS: 5.4) | Sceawere