CVE-2026-42337: MaxKB: Broken Access Control in MaxKB OSS URL Fetch API
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/geturl). The endpoint uses applicationid from the URL path without validating ownership, allowing attackers to perform operations under other applications’ policies. This vulnerability is fixed in 2.8.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MaxKBto a version that resolves this vulnerability.Fixed in 2.8.1 - Compensating control
Until upgraded to MaxKB 2.8.1, restrict network access to the OSS file service URL fetch API endpoint (chat/api/oss/get_url) so only authorized callers can reach it.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42337?
CVE-2026-42337 has a risk score of 52, indicating a moderate severity level.
How do I fix CVE-2026-42337?
To fix CVE-2026-42337, update MaxKB to version 2.8.1 or later where the access control issue has been resolved.
What is the impact of CVE-2026-42337?
CVE-2026-42337 allows attackers to potentially access unauthorized resources through the OSS file service URL fetch API.
Which versions of MaxKB are affected by CVE-2026-42337?
MaxKB versions 2.8.0 and prior are affected by CVE-2026-42337.
Is CVE-2026-42337 related to data exposure?
Yes, CVE-2026-42337 can lead to unauthorized data exposure due to broken access control.