CVE-2026-39910: STACKIT IaaS API Privilege Escalation via Service Account Attachment

Published Jun 8, 2026
·
Updated

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvalidated PUT servers service-accounts endpoint to attach high-privileged service accounts and query the Instance Metadata Service to retrieve OAuth2 tokens, bypassing tenant boundaries and gaining unauthorized control over the entire organization environment.

Affected Software

1 affected component
STACKIT STACKIT IaaS API

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Implement and enforce proper authorization checks on the PUT /servers/service-accounts endpoint so only authorized administrative principals can attach service accounts to virtual machines.

    STACKIT IaaS API (PUT /servers/service-accounts endpoint) authorization_check = enforce
  2. Configuration

    If a code fix is not yet available, temporarily disable the ability to attach service accounts to existing VMs until authorization is implemented and verified.

    STACKIT IaaS API allow_attaching_service_accounts_to_vms = disable (temporary)
  3. Configuration

    Restrict or block access to the Instance Metadata Service from user-controlled VMs that should not be able to retrieve service account OAuth2 tokens (apply network policies or metadata access controls).

    Instance Metadata Service access from tenant VMs = restrict/block
  4. Compensating control

    Restrict access to the servers service-accounts API (e.g., via firewall rules, API gateway, or IAM policies) to trusted administrative networks/roles until a permanent fix is deployed.

  5. Operational

    Audit recent PUT /servers/service-accounts calls and Instance Metadata Service access to identify unauthorized attachments and token retrieval; detach any unauthorized service accounts and remediate affected VMs (e.g., reprovision) as needed.

  6. Operational

    Rotate OAuth2 tokens, service account keys, and any credentials that may have been exposed via the Instance Metadata Service for impacted projects/organization.

Event History

Jun 8, 2026
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Dec 7, 58615
Event
via NVD·02:49 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-39910?

CVE-2026-39910 has a critical severity rating of 9.8.

2

How do I fix CVE-2026-39910?

To fix CVE-2026-39910, ensure that strict authorization checks are implemented for service account attachments in STACKIT IaaS API.

3

What type of vulnerability is CVE-2026-39910?

CVE-2026-39910 is a privilege escalation vulnerability that allows unauthorized escalation of privileges.

4

Who is affected by CVE-2026-39910?

Any users with low privileges in the STACKIT IaaS API environment can potentially be affected by CVE-2026-39910.

5

What impact does CVE-2026-39910 have on organizations?

CVE-2026-39910 can lead to full organizational compromise due to unauthorized privilege escalation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203