Authorization Bypass in MaxKB Open-Source AI Assistant
CVE-2026-77523
7.4HIGH
What is CVE-2026-77523?
MaxKB, an open-source AI assistant for enterprises, contains a vulnerability in versions 2.10.3-lts and earlier that allows authenticated users with model read permissions in an attacker-controlled workspace to exploit the model parameter form route. This exploitation can lead to unauthorized access to sensitive model parameters of other workspaces. Specifically, an attacker can bypass workspace restrictions by supplying a known victim’s model ID, which could compromise workflows relying on these model parameters. Currently, no fixed version is available.
Affected Version(s)
MaxKB <= 2.10.3-lts
