Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85513— StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management

Quick assessment

Affected
StackStorm st2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 StackStorm 的 st2 组件(版本 3.9.0 及更早版本)中已发现一个安全弱点。该问题影响文件 中名为 的函数,涉及 NoOp RBAC 后端组件。由于对参数 的处理不当,导致权限管理存在缺陷。该漏洞可被远程利用,且已有公开的利用方式可供攻击者使用。此前发布的公告 CVE-2022-44009 是针对同一漏洞点的后续报告,但当前问题与之不同:本漏洞不依赖 Jinja RBAC,并且影响的是默认安装配置(RBAC 被禁用的情况)。项目方虽已通过问题报告提前获知此问题,但截至目前尚未作出回应。

CVSS 6.3 · Medium EPSS 0.25% · P16

Affected Version Matrix 10

VendorProduct Version RangeStatus
StackStorm st2 3.0 affected
3.1 affected
3.2 affected
3.3 affected
3.4 affected
3.5 affected
3.6 affected
3.7 affected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85513

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC backend. This manipulation of the argument User causes improper privilege management. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Prior advisory CVE-2022-44009 was reported as a follow-up on the same sink, but this issue is distinct: it needs no Jinja RBAC und affects default install with RBAC disabled. The project was informed of the problem early through an issue report but has not responded yet.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
StackStorm st2 3.0 cpe:2.3:a:stackstorm:st2:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-85513

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85513

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85513 (2)

Vendor Pages for CVE-2026-85513 (1)

Other References for CVE-2026-85513 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85513

No comments yet


Leave a comment