CVE-2026-86259
PoC —Unauthenticated SSRF in OpenMAIC Exposes Cloud Metadata Credentials
OpenMAIC versions before 1.0.1 skip server-side request forgery (SSRF) validation in non-production builds, leaving requests unvalidated by the framework's SSRF checks. Because the bypass requires no authentication, an unauthenticated remote attacker can supply an arbitrary provider URL through the x-base-url header or the baseUrl parameter, causing OpenMAIC to fetch from an attacker-controlled or attacker-chosen endpoint. By pointing that URL at the cloud instance metadata service (for example 169.254.169.254), the attacker can retrieve sensitive cloud credentials and instance metadata belonging to the affected workload. Deployments running non-production builds of OpenMAIC prior to 1.0.1, particularly in cloud environments where metadata services are reachable from the instance, are affected. No public proof-of-concept or in-the-wild exploitation is currently known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Upgrade to OpenMAIC 1.0.1 or later, or run production builds in which SSRF validation remains enabled. Until patched, restrict outbound access from OpenMAIC workloads to cloud metadata endpoints (e.g., 169.254.169.254) and avoid exposing non-production builds to untrusted network traffic. Review cloud credentials and metadata-service access logs for signs of unauthorized retrieval.
| OpenMAIC | before 1.0.1 (non-production builds) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
- Weakness
- CWE-306, CWE-918
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.