Server-Side Request Forgery in OpenMAIC Affects Cloud Metadata Access
CVE-2026-86259
9CRITICAL
What is CVE-2026-86259?
OpenMAIC versions prior to 1.0.1 are vulnerable to a server-side request forgery (SSRF) that permits unauthenticated attackers to bypass validation in non-production environments. By manipulating the x-base-url header or the baseUrl parameter, attackers can potentially access sensitive cloud instance metadata and credentials, which could lead to further exploitation of cloud services. It's crucial for users to update to version 1.0.1 or later to mitigate this risk.
Affected Version(s)
OpenMAIC 0 < 1.0.1
OpenMAIC 1.0.1
