Weak Password Storage in MaxKB AI Assistant by 1Panel
CVE-2026-45413
6.9MEDIUM
What is CVE-2026-45413?
The MaxKB AI assistant, developed by 1Panel, is vulnerable due to its method of storing user passwords using unsalted MD5 hashes prior to version 2.9.1. This poor hashing technique exposes passwords to easy extraction through rainbow tables or accelerated brute force attacks, such as those conducted using hashcat. To mitigate this risk, users are strongly urged to upgrade to version 2.9.1 or later, where this vulnerability has been addressed.
Affected Version(s)
MaxKB < 2.9.1
