Authorization Bypass in MaxKB Open-Source AI Assistant
CVE-2026-77523

7.4HIGH

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77523?

MaxKB, an open-source AI assistant for enterprises, contains a vulnerability in versions 2.10.3-lts and earlier that allows authenticated users with model read permissions in an attacker-controlled workspace to exploit the model parameter form route. This exploitation can lead to unauthorized access to sensitive model parameters of other workspaces. Specifically, an attacker can bypass workspace restrictions by supplying a known victim’s model ID, which could compromise workflows relying on these model parameters. Currently, no fixed version is available.

Affected Version(s)

MaxKB <= 2.10.3-lts

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.