{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-31213432",
  "slug": "cve-2026-86259-openmaic-ssrf-imds-access-code",
  "title": "OpenMAIC unauth SSRF can pull cloud credentials via IMDS",
  "aliases": [
    "CVE-2026-86259",
    "OpenMAIC before 1.0.1 SSRF"
  ],
  "summary": "OpenMAIC before 1.0.1 skips SSRF validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services via x-base-url / baseUrl. Fixed in 1.0.1.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Confirm whether your deployment runs non-production builds where SSRF validation is skipped.",
  "firstObservedAt": "2026-09-06T12:37:50.155Z",
  "lastObservedAt": "2026-09-06T12:37:50.155Z",
  "publishedAt": "2026-09-20T19:00:47.703Z",
  "reviewedAt": "2026-09-20T19:00:38.135Z",
  "expiresAt": "2026-09-06T12:37:50.155Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "ghsa",
      "label": "GitHub Security Advisory GHSA-9m7h-vh2h-rc3w",
      "url": "https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-9m7h-vh2h-rc3w",
      "sourceType": "maintainer_advisory",
      "observedAt": "2026-09-06T12:37:50.155Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-86259",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86259",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-06T12:37:50.155Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-86259-openmaic-ssrf-imds-access-code",
      "sourceType": "other_primary",
      "observedAt": "2026-09-06T12:37:50.155Z"
    }
  ],
  "artifacts": [
    {
      "id": "openmaic",
      "artifactClass": "package",
      "ecosystem": "generic",
      "name": "OpenMAIC",
      "version": ">=0 <1.0.1",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-06T12:37:50.155Z",
      "eventType": "disclosure",
      "summary": "OpenMAIC disclosed CVE-2026-86259 SSRF via environment-gated URL validation.",
      "sourceIds": [
        "ghsa",
        "nvd"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-06T14:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator blog coverage for CVE-2026-86259.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Primarily non-production builds where SSRF validation is skipped.",
    "Fixed version 1.0.1 from GHSA/pack evidence.",
    "HOL blog is operator guidance, not a substitute for the GHSA."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-86259-openmaic-ssrf-imds-access-code/corrections"
}
