PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77516 1Panel-dev CVE debrief

A lowest-role workspace member in MaxKB, an open-source AI assistant for enterprise, can bypass access restrictions to execute a denied tool through the agent or workflow dispatch path. This issue affects versions 2.0.0 through 2.9.2. The dispatch path does not reapply the per-tool grant enforced by dedicated tool routes, allowing the caller to receive credentials carried by the denied tool. No fixed version is available as of this review.

Vendor
1Panel-dev
Product
MaxKB
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-28
Advisory published
2026-09-21
Advisory updated
2026-09-28

Who should care

Defenders responsible for MaxKB deployments, especially those with users having low roles in workspaces, should assess their exposure to this vulnerability and prioritize verification and potential remediation.

Why it matters

Defenders should prioritize verifying exposure in their MaxKB deployments, especially for users with low roles in workspaces, and assess the impact of unauthorized tool execution. This vulnerability allows a lowest-role workspace member to bypass access restrictions and execute a denied tool, potentially leading to unauthorized access to credentials and sensitive information. The evidence is limited, and further verification is required to determine the full scope of the issue.

  • Potential unauthorized tool execution by low-role workspace members
  • Possible exposure of credentials carried by denied tools
  • Need for verification of MaxKB deployment versions and configurations
  • Potential impact on access control and authorization mechanisms

Technical summary

The MaxKB open-source AI assistant for enterprise is vulnerable to an access bypass issue. A lowest-role workspace member can bind a denied tool's identifier through tool_ids, skill_tool_ids, or mcp_tool_ids and execute it through the agent or workflow dispatch path. This is possible because the dispatch path does not reapply the per-tool grant enforced by dedicated tool routes. As a result, the caller can receive credentials carried by the denied tool. This issue affects MaxKB versions 2.0.0 through 2.9.2, and no fixed version is available as of this review.

Defensive priority

Defenders should prioritize verifying exposure in their MaxKB deployments, especially for users with low roles in workspaces, and assess the impact of unauthorized tool execution.

Recommended defensive actions

  • Verify MaxKB deployment versions and configurations to identify potential exposure
  • Restrict access to sensitive tools and workflows for low-role workspace members
  • Monitor for unauthorized tool execution attempts through agent or workflow dispatch paths
  • Consider compensating controls, such as additional authentication or authorization checks
  • Perform an inventory of assets using MaxKB to prioritize remediation
  • Review change management windows for applying patches or mitigations
  • Track and verify source code or vendor advisory updates for MaxKB

Evidence notes

The CVE description and source reference indicate that a lowest-role workspace member can bypass access restrictions to execute a denied tool. The issue is caused by the dispatch path not reapplying the per-tool grant enforced by dedicated tool routes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77516 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77516

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77516 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77516

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.