boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-39910

STACKIT IaaS API Privilege Escalation via Service Account Attachment
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0047   38.4     —
AFFECTED
  Product   Versions     Fixed
  IaaS API  unspecified  —
TIMELINE
  Apr 7   Reserved by VulnCheck
  Jun 8   Published (CNA: VulnCheck)
  Aug 24  RESCORED — CVE-2026-39910 (STACKIT IaaS API). CVSS 9.3 → 8.7 (NVD).
CWE-862 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred

Description

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvalidated PUT servers service-accounts endpoint to attach high-privileged service accounts and query the Instance Metadata Service to retrieve OAuth2 tokens, bypassing tenant boundaries and gaining unauthorized control over the entire organization environment.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 7, 2026ReservedReserved by VulnCheck
June 8, 2026PublishedPublished (CNA: VulnCheck)
August 24, 2026RESCOREDRESCORED — CVE-2026-39910 (STACKIT IaaS API). CVSS 9.3 → 8.7 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
STACKITIaaS API———

Weaknesses

CWE-862

References (2)

Related

Authoritative record: CVE-2026-39910 at cve.org

Vendors: stackit

Weaknesses: CWE-862

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-39910 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.