BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF
This story is from 2026-09-06. It is preserved in the archive; the latest stories are on the live feed.
Originally published at HOL OpenMAIC before 1.0.1 will fetch any URL you put in x-base-url when the SSRF guard is skipped, and the default install has no access code. On a cloud host that means an unauthenticated caller can pull Instance Metadata Service credentials through generation endpoints suc…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-06 13:45 · DEV Community — AI
BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF