CVE-2026-77516: MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member de
Summary
MaxKB, an open-source AI assistant for businesses, has a security flaw in versions 2.0.0 through 2.9.2 where users with low permissions can bypass access controls and execute tools they shouldn't have access to by using special identifiers, then receive sensitive credentials that the tool stored on the server.
Vulnerability Details
5.4(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
network
low
low
none
September 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77516
First tracked: September 21, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 85%