AINewsnow

BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF

This story is from 2026-09-06. It is preserved in the archive; the latest stories are on the live feed.

Originally published at HOL OpenMAIC before 1.0.1 will fetch any URL you put in x-base-url when the SSRF guard is skipped, and the default install has no access code. On a cloud host that means an unauthenticated caller can pull Instance Metadata Service credentials through generation endpoints suc…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-06 13:45 · DEV Community — AI
    BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF

More stories

  1. Introducing Kimi K3 on Amazon Bedrock — AWS Machine Learning Blog
  2. Introducing Amazon SageMaker HyperPod Inference Gateway — AWS Machine Learning Blog
  3. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  4. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  5. Alibaba ships Qwen3.8-Omni-Flash to watch, listen and call tools — r/LocalLLM
  6. NVIDIA CEO Jensen Huang rejects ‘AI will end the world’ claim, yet cautions ‘we should go as fast as we can but...’ — Mint AI
  7. Meet the Data Agent in ChatGPT Work — OpenAI YouTube
  8. AI hallucination of Chinese nuclear components almost led to US military attack — Ars Technica AI

Get the daily brief of stories like this at 6:30 every morning →