CVE-2026-39910 Details
Description
STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvalidated PUT servers service-accounts endpoint to attach high-privileged service accounts and query the Instance Metadata Service to retrieve OAuth2 tokens, bypassing tenant boundaries and gaining unauthorized control over the entire organization environment.
A missing authorization check vulnerability has been identified in the STACKIT IaaS API, affecting versions prior to the 2026-05-28 update. This vulnerability allows authenticated, low-privileged attackers to escalate privileges and compromise entire organizations. By attaching arbitrary service accounts to virtual machines they control, attackers can exploit the unvalidated PUT servers service-accounts endpoint to gain access to high-privileged service accounts. This access enables them to query the Instance Metadata Service for OAuth2 tokens, bypass tenant boundaries, and gain unauthorized control over the organization's environment.
STACKIT has already applied a security patch to address this vulnerability. No action is required from users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 8, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| STACKIT IaaS API | < 2026-05-28 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 24, 2026 | CVE Modified | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | New CVE Received | [email protected] |
Volerion