CVE-2026-79918: MaxKB: Sandbox escape via unhooked fexecve

Published Sep 21, 2026
·
Updated

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LDPRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.

Affected Software

1 affected component
MaxKB<2.10.6-lts

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MaxKB: Sandbox escape via unhooked fexecve to a version that resolves this vulnerability.

    Fixed in 2.10.6-lts

Event History

Sep 21, 2026
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated and able to execute tool code in MaxKB. The attack can be performed remotely and does not require user interaction.

2

What capability does exploitation provide?

An attacker can invoke fexecve to create a process outside the ToolExecutor sandbox's intended subprocess-creation policy. The reported impact includes limited effects on confidentiality, integrity, and availability.

3

Are default deployments affected?

The available information does not state whether tool-code execution is enabled or reachable in the default configuration. Exposure depends on whether authenticated users can execute tool code through ToolExecutor.

4

What should be done to remediate the issue?

Upgrade MaxKB to version 2.10.6-lts, which fixes the missing fexecve hook. If an immediate upgrade is not possible, restrict access to users who can execute tool code.

5

How can I determine whether an installation is affected?

Installations running a version earlier than 2.10.6-lts are affected if authenticated users can execute tool code. Version 2.10.6-lts contains the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203