CVE-2026-79917: MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation

Published Sep 21, 2026
·
Updated

MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{applicationid}/chat/{chatid}/sharechat verifies that a conversation exists but does not verify that it belongs to the authenticated chatuserid or to the application bound to the caller's token. An attacker with any chat token and a known victim chatid can create an unauthenticated public ChatShareLink exposing the victim's conversation and can create PublicFileAccess state that makes associated files retrievable without credentials, with no available revoke path. No fixed version is available as of this review.

Affected Software

1 affected component
MaxKB>=2.7.0<=2.10.4-lts

Event History

Sep 21, 2026
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments running MaxKB versions 2.7.0 through 2.10.4-lts are affected. Exploitation requires an attacker to possess any valid chat token and know a victim conversation's chat_id.

2

What can an attacker do with a victim chat ID?

The attacker can call the share endpoint to create an unauthenticated public share link for the victim's conversation. Associated files may also become retrievable without credentials through PublicFileAccess state.

3

Does the attacker need to be the conversation owner or use a token for the same application?

No. The endpoint checks that the conversation exists but does not verify ownership against the authenticated chat_user_id or verify that the conversation belongs to the application associated with the caller's token.

4

Can exposure be revoked after a malicious share link is created?

The available information states that there is no revoke path for the created public file access state. No fixed MaxKB version was available as of the review.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203