{"type":"bundle","id":"bundle--123bab81-94ed-5d18-9b06-40afaa521b79","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--86f0828d-114b-5778-a3a2-0425520326f4","created":"2026-09-20T19:00:47.703Z","modified":"2026-09-20T19:00:47.703Z","name":"OpenMAIC unauth SSRF can pull cloud credentials via IMDS","description":"OpenMAIC before 1.0.1 skips SSRF validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services via x-base-url / baseUrl. Fixed in 1.0.1.","aliases":["CVE-2026-86259","OpenMAIC before 1.0.1 SSRF"],"first_seen":"2026-09-06T12:37:50.155Z","last_seen":"2026-09-06T12:37:50.155Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"GitHub Security Advisory GHSA-9m7h-vh2h-rc3w","url":"https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-9m7h-vh2h-rc3w"},{"source_name":"NVD CVE-2026-86259","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86259"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-86259-openmaic-ssrf-imds-access-code"}]}]}