CVE-2026-77517: CWE-639: Authorization Bypass Through User-Controlled Key in 1Panel-dev MaxKB
CVE-2026-77517 is an authorization bypass vulnerability in MaxKB, an open-source AI assistant for enterprise. Versions from 2.0.0 through 2.10.2-lts are affected. The issue arises because document and paragraph routes authorize only the knowledge_id in the request path but do not verify that the document or paragraph actually belongs to that knowledge base. This allows a user with access to a known document or paragraph UUID to read or modify content in another user's knowledge base by using an attacker-controlled knowledge base path. No fix is currently available.
AI Analysis
Technical Summary
MaxKB versions 2.0.0 through 2.10.2-lts contain an authorization bypass vulnerability (CWE-639, CWE-862) where the API endpoints for documents and paragraphs authorize based solely on the knowledge_id in the request path. However, when querying the target Document or Paragraph by their respective IDs, the system does not confirm that these objects belong to the authorized knowledge base. Consequently, a normal workspace user who knows a victim's document or paragraph UUID can exploit this flaw by using an attacker-owned knowledge base path to access or modify another user's knowledge base content. This vulnerability has a CVSS 3.1 base score of 5.4, indicating medium severity. No patches or fixed versions are currently available.
Potential Impact
An attacker with normal workspace user privileges can read or modify documents or paragraphs in another user's knowledge base if they know the UUID of the target document or paragraph. This leads to unauthorized disclosure and modification of content across knowledge bases within the MaxKB environment. There is no indication of availability impact or known active exploitation in the wild.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should monitor the vendor's advisories for updates. Until a fix is released, restrict access to knowledge base UUIDs and limit sharing of document or paragraph identifiers to trusted users only to reduce the risk of exploitation.
CVE-2026-77517: CWE-639: Authorization Bypass Through User-Controlled Key in 1Panel-dev MaxKB
Description
CVE-2026-77517 is an authorization bypass vulnerability in MaxKB, an open-source AI assistant for enterprise. Versions from 2.0.0 through 2.10.2-lts are affected. The issue arises because document and paragraph routes authorize only the knowledge_id in the request path but do not verify that the document or paragraph actually belongs to that knowledge base. This allows a user with access to a known document or paragraph UUID to read or modify content in another user's knowledge base by using an attacker-controlled knowledge base path. No fix is currently available.
CVSS v3.1
Score 5.4medium
Affected software
1Panel-dev
MaxKB
pkg:github/1panel-dev/MaxKBRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MaxKB versions 2.0.0 through 2.10.2-lts contain an authorization bypass vulnerability (CWE-639, CWE-862) where the API endpoints for documents and paragraphs authorize based solely on the knowledge_id in the request path. However, when querying the target Document or Paragraph by their respective IDs, the system does not confirm that these objects belong to the authorized knowledge base. Consequently, a normal workspace user who knows a victim's document or paragraph UUID can exploit this flaw by using an attacker-owned knowledge base path to access or modify another user's knowledge base content. This vulnerability has a CVSS 3.1 base score of 5.4, indicating medium severity. No patches or fixed versions are currently available.
Potential Impact
An attacker with normal workspace user privileges can read or modify documents or paragraphs in another user's knowledge base if they know the UUID of the target document or paragraph. This leads to unauthorized disclosure and modification of content across knowledge bases within the MaxKB environment. There is no indication of availability impact or known active exploitation in the wild.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should monitor the vendor's advisories for updates. Until a fix is released, restrict access to knowledge base UUIDs and limit sharing of document or paragraph identifiers to trusted users only to reduce the risk of exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T20:23:02.507Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab1abbb55bf5e2cf58b467c
Added to database: 09/21/2026, 22:12:11 UTC
Last enriched: 09/21/2026, 22:13:44 UTC
Last updated: 09/21/2026, 23:43:52 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.