Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a missing authorization check in the STACKIT IaaS API that could allow authenticated attackers to gain full control of an organization's environment. The vulnerability could enable an attacker to attach unauthorized service accounts to virtual machines, subsequently enabling them to steal sensitive tokens and bypass security controls to compromise the entire organization. The main concern is confirming relevance and exposure within your environment.
- Attackers can gain broad control.
- Limits visibility into privileged actions.
- Confirm if this API is in use.
Attack Path
How an attacker could exploit the issue
An attacker with initial low-privileged access to the STACKIT IaaS API could escalate their privileges. This is achieved by exploiting a missing authorization check in a specific endpoint, allowing them to attach arbitrary service accounts to virtual machines they control. By then interacting with the Instance Metadata Service, the attacker can retrieve sensitive tokens, ultimately enabling them to gain unauthorized control over the entire organization's environment.
- Entry condition: Authenticated, low-privileged access.
- Trigger point: Attaching service accounts to virtual machines.
- Resulting risk: Full organization compromise.
Live Threat
Current exploitation, exposure, and threat context
Authenticated low-privileged attackers could gain full control over an organization's environment by attaching high-privileged service accounts to virtual machines they control. This could allow them to access and retrieve sensitive OAuth2 tokens, bypassing tenant boundaries and compromising the entire environment.
- Organization-wide control.
- Attach arbitrary service accounts.
- Full organization compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in the STACKIT IaaS API could allow authenticated, low-privileged users to escalate their privileges and compromise the entire organization by attaching arbitrary service accounts to virtual machines. The first step is to identify all instances of the affected API, determine their reachability and business criticality, assign an accountable owner, and then plan remediation based on the assessed risk.
- Infrastructure and Platform teams likely own this.
- Verify API endpoint exposure and configuration.
- Plan controlled remediation based on risk.