CVE-2026-77517: MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base

Published Sep 21, 2026
·
Updated

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledgeid in the request path, then query the target Document by documentid or Paragraph by paragraphid without confirming that the object belongs to that knowledge base. A normal workspace user with a known victim document or paragraph UUID can use an attacker-owned knowledge-base path to read or modify content in another user's knowledge base. No fixed version is available as of this review.

Affected Software

1 affected component
MaxKB MaxKB>=2.0.0<=2.10.2-lts

Event History

Sep 21, 2026
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A normal workspace user can exploit it; administrative privileges are not required. The attacker must know a victim document or paragraph UUID.

2

Are all affected deployments exposed by default?

The issue affects document and paragraph routes in MaxKB versions 2.0.0 through 2.10.2-lts because authorization checks the knowledge base ID in the request path but does not verify the target object's ownership. Exposure requires an attacker to be able to submit requests as a workspace user and possess a target UUID.

3

What can an attacker do with a target UUID?

An attacker can use a knowledge-base path they control to read or modify documents and paragraphs belonging to another user's knowledge base. The stated impact is limited to confidentiality and integrity; no availability impact is described.

4

Is a fix available?

No fixed version was available at the time of review. Organizations using affected versions should treat cross-knowledge-base document and paragraph access as unsafe until a vendor fix is available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203