PT-2026-86529 · Openmaic · Openmaic
CVE-2026-86259
·
Published
2026-09-06
·
Updated
2026-09-06
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenMAIC versions prior to 1.0.1
Description
In non-production builds, the software fails to perform server-side request forgery (SSRF) validation. This allows unauthenticated attackers to access cloud instance metadata services by providing arbitrary provider URLs through the
x-base-url header or the baseUrl parameter. This flaw can be used to retrieve sensitive cloud credentials and metadata.Recommendations
Update to version 1.0.1.
Configure the
ACCESS CODE setting to restrict unauthorized access.Exploit
Fix
Missing Authentication
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openmaic