PatchSiren cyber security CVE debrief
CVE-2026-77516 1Panel-dev CVE debrief
A lowest-role workspace member in MaxKB, an open-source AI assistant for enterprise, can bypass access restrictions to execute a denied tool through the agent or workflow dispatch path. This issue affects versions 2.0.0 through 2.9.2. The dispatch path does not reapply the per-tool grant enforced by dedicated tool routes, allowing the caller to receive credentials carried by the denied tool. No fixed version is available as of this review.
- Vendor
- 1Panel-dev
- Product
- MaxKB
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for MaxKB deployments, especially those with users having low roles in workspaces, should assess their exposure to this vulnerability and prioritize verification and potential remediation.
Why it matters
Defenders should prioritize verifying exposure in their MaxKB deployments, especially for users with low roles in workspaces, and assess the impact of unauthorized tool execution. This vulnerability allows a lowest-role workspace member to bypass access restrictions and execute a denied tool, potentially leading to unauthorized access to credentials and sensitive information. The evidence is limited, and further verification is required to determine the full scope of the issue.
- Potential unauthorized tool execution by low-role workspace members
- Possible exposure of credentials carried by denied tools
- Need for verification of MaxKB deployment versions and configurations
- Potential impact on access control and authorization mechanisms
Technical summary
The MaxKB open-source AI assistant for enterprise is vulnerable to an access bypass issue. A lowest-role workspace member can bind a denied tool's identifier through tool_ids, skill_tool_ids, or mcp_tool_ids and execute it through the agent or workflow dispatch path. This is possible because the dispatch path does not reapply the per-tool grant enforced by dedicated tool routes. As a result, the caller can receive credentials carried by the denied tool. This issue affects MaxKB versions 2.0.0 through 2.9.2, and no fixed version is available as of this review.
Defensive priority
Defenders should prioritize verifying exposure in their MaxKB deployments, especially for users with low roles in workspaces, and assess the impact of unauthorized tool execution.
Recommended defensive actions
- Verify MaxKB deployment versions and configurations to identify potential exposure
- Restrict access to sensitive tools and workflows for low-role workspace members
- Monitor for unauthorized tool execution attempts through agent or workflow dispatch paths
- Consider compensating controls, such as additional authentication or authorization checks
- Perform an inventory of assets using MaxKB to prioritize remediation
- Review change management windows for applying patches or mitigations
- Track and verify source code or vendor advisory updates for MaxKB
Evidence notes
The CVE description and source reference indicate that a lowest-role workspace member can bypass access restrictions to execute a denied tool. The issue is caused by the dispatch path not reapplying the per-tool grant enforced by dedicated tool routes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77516 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77516
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77516 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77516
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-383v-fx78-pphm
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.