CVE-2026-39910
STACKIT’s IaaS API has a missing authorization check that lets an attacker with low privileges attach high‑privileged service accounts to virtual machines they control. By exploiting the unvalidated PUT /servers/service-accounts endpoint, the attacker can then retrieve OAuth2 tokens from the Instance Metadata Service and take over the entire organization’s environment.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
STACKIT IaaS API users – organizations that host virtual machines on STACKIT’s infrastructure and rely on the API to manage service accounts.
Real-world impact
An attacker can gain full control over an organization’s cloud resources, including the ability to read, modify, or delete data, launch malicious workloads, and exfiltrate sensitive information, all without needing to bypass tenant boundaries.
Why this severity
The CVSS score of 9.3 reflects the vulnerability’s high impact on confidentiality, integrity, and availability. It allows an attacker to elevate privileges from a low level to full organization control, making it a critical security risk.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 8, 2026 · Jun 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.