{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/openmaic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openmaic:openmaic:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-86259"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenMAIC (\u003c 1.0.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ssrf","cloud-security"],"_cs_type":"advisory","_cs_vendors":["OpenMAIC"],"content_html":"\u003cp\u003eOpenMAIC versions prior to 1.0.1 are vulnerable to a Server-Side Request Forgery (SSRF) flaw due to insufficient validation logic in non-production builds. The vulnerability arises because the application fails to properly sanitize or validate user-supplied input when processing outgoing requests. Unauthenticated attackers can leverage this oversight by injecting malicious values into the 'x-base-url' HTTP header or the 'baseUrl' query parameter.\u003c/p\u003e\n\u003cp\u003eBy forcing the OpenMAIC server to redirect requests to internal endpoints, specifically cloud instance metadata services (such as those hosted on 169.254.169.254 in AWS, GCP, or Azure environments), an attacker can retrieve sensitive information, including temporary cloud identity credentials, environment variables, and instance configuration data. This vulnerability is particularly critical for deployments that rely on non-production builds for testing or staging purposes, as it provides a direct pathway for lateral movement and privilege escalation within the cloud environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to retrieve sensitive cloud credentials and metadata, potentially leading to full compromise of the affected cloud instance's identity and subsequent unauthorized access to broader cloud infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all OpenMAIC installations to version 1.0.1 or later immediately to patch the SSRF validation logic.\u003c/li\u003e\n\u003cli\u003eAudit all non-production deployments of OpenMAIC to ensure they are not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering at the cloud network layer to block access to sensitive metadata services (169.254.169.254) from non-essential application containers or VMs.\u003c/li\u003e\n\u003cli\u003eReview logs for HTTP requests containing suspicious values in the 'x-base-url' header or 'baseUrl' parameter directed at internal network resources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-06T14:46:37Z","date_published":"2026-09-06T14:46:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openmaic-ssrf/","summary":"OpenMAIC versions prior to 1.0.1 contain a vulnerability in non-production builds that allows unauthenticated attackers to perform SSRF by manipulating request headers or parameters to access cloud metadata services.","title":"Unauthenticated SSRF Vulnerability in OpenMAIC","url":"https://feed.craftedsignal.io/briefs/2026-09-openmaic-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenMAIC","version":"https://jsonfeed.org/version/1.1"}