Data Exposure in MaxKB AI Assistant by 1Panel
CVE-2026-77520

5.4MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77520?

In the MaxKB AI assistant, normal users can exploit a data exposure vulnerability allowing them to access another user's application_id through the homepage application question-ranking endpoint. This issue occurs when the victim's application has activity within the specified date range and if the attacker is aware of or can guess the application’s name. Even though certain application routes restrict access, the vulnerability remains in the ability to create and publish a workflow application that can utilize the disclosed identifier, thereby triggering workflows that access the victim application’s output without proper permission checks. Currently, there is no fixed version for this vulnerability.

Affected Version(s)

MaxKB <= 2.10.2-lts

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.