CVE-2026-77516
Deferred Deferred - Pending Action

MaxKB Workspace Member Tool Execution via Bypassed Permissions

Vulnerability report for CVE-2026-77516, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: GitHub, Inc.

Description

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can still bind its identifier through tool_ids, skill_tool_ids, or mcp_tool_ids and execute it through the agent or workflow dispatch path. The dispatch path does not reapply the per-tool grant enforced by dedicated tool routes, and tool execution decrypts server-side init_params, allowing the caller to receive credentials carried by the denied tool. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
maxkb maxkb From 2.0.0 (inc) to 2.9.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MaxKB versions 2.0.0 through 2.9.2 have a flaw where a low-privilege workspace member can bypass tool access restrictions. Even if denied permission to a tool, they can still bind its identifier and execute it through agent or workflow paths. The system fails to reapply tool-specific permissions during dispatch, allowing unauthorized access to credentials carried by the tool.

Impact Analysis

An attacker with low-level workspace access could exploit this to execute restricted tools and gain access to sensitive credentials or data. This could lead to data breaches, unauthorized actions, or privilege escalation within the MaxKB system.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data, potentially breaching GDPR's data protection principles or HIPAA's access controls. Organizations using MaxKB may face regulatory penalties or audit failures due to insufficient access controls.

Mitigation Strategies

Upgrade MaxKB to a version beyond 2.9.2 if available. If no fixed version exists, restrict workspace member roles to prevent unauthorized tool access. Monitor agent or workflow dispatch paths for unusual tool execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77516. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart