Authentication Bypass in MaxKB Open-Source AI Assistant
CVE-2026-77519

5.4MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77519?

MaxKB, an open-source AI assistant, is vulnerable to an authentication bypass that allows the initialization of the MCP endpoint with a non-permanent application key even after its expiration. The vulnerability arises due to insufficient checks on the application API key, where only its secret and active status are considered. As a result, an attacker can exploit this weakness to access application tool metadata, invoke services, and create persistent chat states, despite restrictions that would normally apply to expired keys. There is currently no fixed version.

Affected Version(s)

MaxKB <= 2.10.2-lts

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.