CVE-2026-77518: CWE-862: Missing Authorization in 1Panel-dev MaxKB
MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because it does not apply the per-resource authorization used by the list route. The response includes Tool.code, which may contain MCP server configuration and headers, and an attacker who can create or edit an attacker-owned workflow can place the same foreign mcp_tool_id in a workflow mcp-node so workflow debug uses the owner's MCP configuration without verifying permission to use that tool. No fixed version is available as of this review.
AI Analysis
Technical Summary
MaxKB, an open-source AI assistant for enterprise, suffers from a missing authorization vulnerability (CWE-862) in versions 2.10.2-lts and earlier. The tool-detail API route does not enforce per-resource authorization, enabling a normal workspace user to retrieve hidden tools of other users if they know the active MCP tool_id. The response leaks Tool.code, potentially exposing MCP server configuration and headers. Furthermore, an attacker with workflow creation or editing privileges can insert a foreign mcp_tool_id into a workflow node, causing workflow debug to use the owner's MCP configuration without verifying access rights. As of the review date, no patched version is available.
Potential Impact
An attacker with normal workspace user privileges can access hidden tools belonging to other users, potentially exposing sensitive MCP server configuration and headers. This unauthorized access could lead to misuse of another user's MCP configuration in workflows, possibly impacting confidentiality. The vulnerability does not affect integrity or availability directly. No known exploits are reported in the wild.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should monitor vendor advisories for updates. Until a fix is released, restrict workflow creation and editing permissions to trusted users only to reduce risk. Avoid sharing MCP tool_ids publicly or with untrusted users.
CVE-2026-77518: CWE-862: Missing Authorization in 1Panel-dev MaxKB
Description
MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because it does not apply the per-resource authorization used by the list route. The response includes Tool.code, which may contain MCP server configuration and headers, and an attacker who can create or edit an attacker-owned workflow can place the same foreign mcp_tool_id in a workflow mcp-node so workflow debug uses the owner's MCP configuration without verifying permission to use that tool. No fixed version is available as of this review.
CVSS v3.1
Score 5.0medium
Affected software
1Panel-dev
MaxKB
pkg:github/1panel-dev/MaxKBRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MaxKB, an open-source AI assistant for enterprise, suffers from a missing authorization vulnerability (CWE-862) in versions 2.10.2-lts and earlier. The tool-detail API route does not enforce per-resource authorization, enabling a normal workspace user to retrieve hidden tools of other users if they know the active MCP tool_id. The response leaks Tool.code, potentially exposing MCP server configuration and headers. Furthermore, an attacker with workflow creation or editing privileges can insert a foreign mcp_tool_id into a workflow node, causing workflow debug to use the owner's MCP configuration without verifying access rights. As of the review date, no patched version is available.
Potential Impact
An attacker with normal workspace user privileges can access hidden tools belonging to other users, potentially exposing sensitive MCP server configuration and headers. This unauthorized access could lead to misuse of another user's MCP configuration in workflows, possibly impacting confidentiality. The vulnerability does not affect integrity or availability directly. No known exploits are reported in the wild.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should monitor vendor advisories for updates. Until a fix is released, restrict workflow creation and editing permissions to trusted users only to reduce risk. Avoid sharing MCP tool_ids publicly or with untrusted users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T20:23:02.507Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab197cf55bf5e2cf5736875
Added to database: 09/21/2026, 20:47:11 UTC
Last enriched: 09/21/2026, 21:01:49 UTC
Last updated: 09/21/2026, 23:40:29 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.