Injection Vulnerability in MaxKB Open Source AI Assistant
CVE-2026-79916

9.1CRITICAL

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-79916?

MaxKB, an open-source AI assistant for enterprises, is susceptible to an injection vulnerability affecting its AWS credentials management. Prior to version 2.10.5-lts, authenticated users could inject control characters into the AWS access_key_id and secret_access_key fields. This flaw permits an attacker to manipulate the AWS credentials at /root/.aws/credentials, enabling them to create a new AWS profile with a credential_process that can execute arbitrary commands with root privileges during model validation requests. This vulnerability has been addressed in the recently released version 2.10.5-lts.

Affected Version(s)

MaxKB < 2.10.5-lts

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.