Junglewise Threat Intelligence

CVE-2026-42337: 1Panel-dev MaxKB broken access control in OSS URL fetch API

CVE-2026-42337 · Severity: info · CVSS 5.3 · Published 2026-05-26

Technologies: 1Panel-dev MaxKB. Vendors: 1Panel-dev.

Executive brief

MaxKB is an open-source AI assistant platform used by enterprises to build and manage AI-powered Q&A applications. A security flaw in the file service component allows a logged-in user to bypass security boundaries and access data or policies belonging to other applications within the same system. This could lead to unauthorized access to sensitive configuration data or internal files, compromising the isolation between different business units or tenants.

Technical details

A broken access control vulnerability exists in the MaxKB OSS file service URL fetch API endpoint (/chat/api/oss/get_url). The GetUrlView.get() method extracts the application_id parameter directly from the URL path and passes it to the get_url_content() function without verifying if the authenticated user's token has permission to access that specific application. This allows an authenticated attacker to perform cross-application privilege bypass by supplying an arbitrary application ID. The system then loads the target application's policy and performs URL fetch operations within that unauthorized context. The issue is resolved in version 2.8.1 by enforcing application ownership validation at the view layer.

Affected products

  • 1Panel-dev MaxKB <= 2.8.0

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published by vendor
  • 2026-05-26: disclosed: CVE published to NVD
  • 2026-05-26: patched: Fix released in version 2.8.1

References

Related threats