PT-2026-86529 · Openmaic · Openmaic

CVE-2026-86259

·

Published

2026-09-06

·

Updated

2026-09-06

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenMAIC versions prior to 1.0.1
Description In non-production builds, the software fails to perform server-side request forgery (SSRF) validation. This allows unauthenticated attackers to access cloud instance metadata services by providing arbitrary provider URLs through the x-base-url header or the baseUrl parameter. This flaw can be used to retrieve sensitive cloud credentials and metadata.
Recommendations Update to version 1.0.1. Configure the ACCESS CODE setting to restrict unauthorized access.

Exploit

Fix

Missing Authentication

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86259
GHSA-9M7H-VH2H-RC3W

Affected Products

Openmaic