Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 06 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata. | |
| Title | OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation | |
| Weaknesses | CWE-306 CWE-918 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-06T12:37:50.155Z
Reserved: 2026-09-06T11:35:19.317Z
Link: CVE-2026-86259
No data.
Status : Received
Published: 2026-09-06T13:17:10.963
Modified: 2026-09-06T13:17:10.963
Link: CVE-2026-86259
No data.
OpenCVE Enrichment
Updated: 2026-09-06T13:30:07Z