Data Exposure in MaxKB AI Assistant by 1Panel
CVE-2026-77520
5.4MEDIUM
What is CVE-2026-77520?
In the MaxKB AI assistant, normal users can exploit a data exposure vulnerability allowing them to access another user's application_id through the homepage application question-ranking endpoint. This issue occurs when the victim's application has activity within the specified date range and if the attacker is aware of or can guess the application’s name. Even though certain application routes restrict access, the vulnerability remains in the ability to create and publish a workflow application that can utilize the disclosed identifier, thereby triggering workflows that access the victim application’s output without proper permission checks. Currently, there is no fixed version for this vulnerability.
Affected Version(s)
MaxKB <= 2.10.2-lts
