Authorization Flaw in MaxKB Open Source Enterprise AI Assistant
CVE-2026-77525

4.2MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77525?

An authorization issue in MaxKB, an open-source AI assistant for enterprise, allows attackers to access and manipulate chat records. In versions 2.10.2-lts and earlier, management chat-record routes improperly authorize access using 'application_id', failing to validate if the chat belongs to the authorized application. This allows regular users to exploit this weakness to retrieve chat records by using known 'chat_id' values, consequently compromising data privacy. An attacker with access to specific knowledge bases can also use the 'add_knowledge' functionality to illicitly copy content from victim records, highlighting a significant security concern without a fix currently available.

Affected Version(s)

MaxKB <= 2.10.2-lts

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.