Unauthorized Access Flaw in MaxKB Open-Source AI Assistant
CVE-2026-79917

6.5MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-79917?

The MaxKB open-source AI assistant contains a security flaw that allows attackers to exploit shared conversations. In versions 2.7.0 through 2.10.4-lts, the system verifies the existence of a conversation but fails to confirm whether it belongs to the authenticated user or is associated with the application related to the caller's token. This gap permits an attacker with any chat token and knowledge of a victim's chat ID to generate a public link, thus exposing private conversations. Furthermore, the vulnerability allows creating a state of public file access, enabling retrieval of associated files without any user credentials, and there is no method to revoke this access once granted.

Affected Version(s)

MaxKB >= 2.7.0, <= 2.10.4-lts

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.