CRITICAL 9.0 NVD

CVE-2026-86259

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.

References

Published: 2026-09-06 · Source: NVD · Feed updated: 2026-09-06
This critical severity vulnerability with a CVSS score of 9.0 was published on 2026-09-06 via NVD.

Risk Timeline

CVE Disclosed2026-09-06 · -1 days ago

Remediation Resources

vulnfeed aggregates 10006 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.