{"data":{"id":"774c20f0-d345-4e6f-ab15-5c3647761463","title":"CVE-2026-77516: MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member de","summary":"MaxKB, an open-source AI assistant for businesses, has a security flaw in versions 2.0.0 through 2.9.2 where users with low permissions can bypass access controls and execute tools they shouldn't have access to by using special identifiers, then receive sensitive credentials that the tool stored on the server.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77516","publishedAt":"2026-09-21T21:17:10.143Z","cveId":"CVE-2026-77516","cweIds":["CWE-639","CWE-862"],"cvssScore":"5.4","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["MaxKB"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T21:17:10.143Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}