Junglewise Threat Intelligence

CVE-2026-77517: MaxKB authorization bypass in document and paragraph routes

CVE-2026-77517 · Severity: medium · CVSS 5.4 · Published 2026-09-21

Technologies: 1Panel-dev MaxKB. Vendors: 1Panel-dev.

Executive brief

MaxKB is an open-source AI assistant platform used by enterprises to manage knowledge bases. A flaw in access controls allows a legitimate workspace user to read and modify documents and paragraphs in other users' knowledge bases within the same workspace by bypassing authorization checks. This permits unauthorized access to sensitive documents and the ability to tamper with another user's content.

Technical details

The vulnerability is an insecure direct object reference (IDOR) where document and paragraph operate handlers validate only the knowledge_id in the URL path but fail to verify that the target document or paragraph object actually belongs to that knowledge base. An attacker with a valid user token can construct requests using their own knowledge base ID in the path while supplying another user's document or paragraph UUID in the request, bypassing the authorization gate. The fix requires binding the document and paragraph IDs to the knowledge_id in the authorization check, similar to the pattern already correctly implemented in the batch document and create paragraph endpoints.

Affected products

  • 1Panel-dev MaxKB 2.0.0 through 2.10.2-lts

Timeline

  • 2026-09-21: disclosed

References

Related threats