Authorization Flaw in MaxKB Open-Source AI Assistant
CVE-2026-77518

5MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77518?

MaxKB, an open-source AI assistant designed for enterprise use, contains a significant authorization flaw that impacts versions up to 2.10.2-lts. In this vulnerability, a regular workspace user can gain unauthorized access to another user's hidden MCP tool if they know its active tool_id. The flaw arises due to the lack of per-resource authorization for the tool-detail route, allowing attackers to retrieve sensitive server configurations and headers. By exploiting the ability to create or modify workflows, an attacker could integrate a foreign mcp_tool_id into their workflow, potentially utilizing another user's MCP configuration without appropriate permissions. Currently, no patched version is available to rectify this issue.

Affected Version(s)

MaxKB <= 2.10.2-lts

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.