CVE-2026-45413: MaxKB: Unsalted MD5 Password Hashing
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow tables or GPU-accelerated brute force (hashcat). This vulnerability is fixed in 2.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MaxKBto a version that resolves this vulnerability.Fixed in 2.9.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45413?
CVE-2026-45413 has a risk score of 62, indicating a moderate level of severity.
How do I fix CVE-2026-45413?
To fix CVE-2026-45413, upgrade MaxKB to version 2.9.1 or later.
What are the risks associated with CVE-2026-45413?
The risks include the exposure of user passwords to rainbow table or brute-force attacks due to the use of unsalted MD5 hashing.
Who is affected by CVE-2026-45413?
Any user of MaxKB versions prior to 2.9.1 is affected by CVE-2026-45413.
What specific vulnerability does CVE-2026-45413 address?
CVE-2026-45413 addresses the insecure storage of user passwords using unsalted MD5 hashes.