Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manipulation of the argument api_key_api.user leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | StackStorm st2 API Key auth.py privileges management | |
| First Time appeared |
Stackstorm
Stackstorm st2 |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:stackstorm:st2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Stackstorm
Stackstorm st2 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-04T18:00:46.923Z
Reserved: 2026-09-04T05:35:46.391Z
Link: CVE-2026-85514
Updated: 2026-09-04T18:00:11.447Z
Status : Deferred
Published: 2026-09-04T13:20:11.300
Modified: 2026-09-04T18:18:03.303
Link: CVE-2026-85514
No data.
OpenCVE Enrichment
Updated: 2026-09-04T16:00:05Z