Authorization Flaw in MaxKB Open Source Enterprise AI Assistant
CVE-2026-77525
4.2MEDIUM
What is CVE-2026-77525?
An authorization issue in MaxKB, an open-source AI assistant for enterprise, allows attackers to access and manipulate chat records. In versions 2.10.2-lts and earlier, management chat-record routes improperly authorize access using 'application_id', failing to validate if the chat belongs to the authorized application. This allows regular users to exploit this weakness to retrieve chat records by using known 'chat_id' values, consequently compromising data privacy. An attacker with access to specific knowledge bases can also use the 'add_knowledge' functionality to illicitly copy content from victim records, highlighting a significant security concern without a fix currently available.
Affected Version(s)
MaxKB <= 2.10.2-lts
