OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 06 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata. | |
| Title | OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation | |
| Weaknesses | CWE-306 CWE-918 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-06T12:37:50.155Z
Reserved: 2026-09-06T11:35:19.317Z
Link: CVE-2026-86259
No data.
Status : Received
Published: 2026-09-06T13:17:10.963
Modified: 2026-09-06T13:17:10.963
Link: CVE-2026-86259
No data.
OpenCVE Enrichment
Updated: 2026-09-06T13:30:07Z