Vulnerability in MaxKB AI Assistant by 1Panel-Dev Compromises Tool Access
CVE-2026-77516

5.4MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77516?

MaxKB, an open-source AI assistant developed by 1Panel-Dev, has a security flaw that affects versions 2.0.0 through 2.9.2. This vulnerability allows lower-role workspace members to bypass tool access restrictions. Even when a user is denied access to a specific tool via WorkspaceUserResourcePermission, they can still bind tool identifiers through various IDs such as tool_ids and skill_tool_ids. This enables unauthorized execution of the tool via agent or workflow dispatch paths. Additionally, the dispatch mechanism fails to reapply access controls enforced during standard tool routes, allowing the execution of the tool to decrypt sensitive server-side parameters, subsequently exposing credentials that are intended to be protected. Currently, no patched version is available.

Affected Version(s)

MaxKB >= 2.0.0, <= 2.9.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.