Improper Privilege Management in StackStorm API Key Handler
CVE-2026-85514
Key Information:
- Vendor
Stackstorm
- Status
- Vendor
- CVE Published:
- 4 September 2026
Badges
What is CVE-2026-85514?
A vulnerability has been identified in the StackStorm st2 API Key Handler, affecting versions up to 3.9.0. This issue arises from an unidentified flaw in the file st2api/st2api/controllers/v1/auth.py, specifically concerning the manipulation of the api_key_api.user argument, leading to improper privilege management. An attacker can exploit this vulnerability remotely, which poses a significant risk to the integrity of the system. The vulnerability has been publicly disclosed, and despite early notification to the project team through an issue report, no response has been received regarding remediation.
Affected Version(s)
st2 3.0
st2 3.1
st2 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
