Junglewise Threat Intelligence

CVE-2026-39910: STACKIT IaaS API privilege escalation via service account attachment

CVE-2026-39910 · Severity: critical · CVSS 9.8 · Published 2026-06-08

Executive brief

A security flaw in the STACKIT cloud infrastructure API allows users with limited access to gain full control over an entire organization's cloud environment. By attaching high-privileged service accounts to their own virtual machines, an attacker can steal security tokens and bypass security boundaries. This could lead to the theft of sensitive data, unauthorized modification of infrastructure, or a complete takeover of cloud operations.

Technical details

A missing authorization check in the STACKIT IaaS API allows for privilege escalation via the 'PUT servers service-accounts' endpoint. The root cause is a failure to validate whether the requesting user has permission to use a specific service account when attaching it to a virtual machine. An authenticated attacker can exploit this by attaching a high-privileged service account to a VM they control and then querying the Instance Metadata Service (IMDS) to retrieve OAuth2 tokens. This allows the attacker to bypass tenant boundaries and gain unauthorized administrative control over the entire organization environment. The vulnerability was addressed in the service update released on May 28, 2026.

Affected products

  • STACKIT IaaS API versions prior to 2026-05-28

Timeline

  • 2026-05-28: patched: Service updated to address the vulnerability.
  • 2026-06-08: disclosed: Vulnerability details published.

References