Weak Password Storage in MaxKB AI Assistant by 1Panel
CVE-2026-45413

6.9MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-45413?

The MaxKB AI assistant, developed by 1Panel, is vulnerable due to its method of storing user passwords using unsalted MD5 hashes prior to version 2.9.1. This poor hashing technique exposes passwords to easy extraction through rainbow tables or accelerated brute force attacks, such as those conducted using hashcat. To mitigate this risk, users are strongly urged to upgrade to version 2.9.1 or later, where this vulnerability has been addressed.

Affected Version(s)

MaxKB < 2.9.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.