CVE-2026-77520
5.4 MEDIUMpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- An attacker can obtain another user's application_id by exploiting a vulnerability in MaxKB’s homepage application question-ranking endpoint, allowing them to access sensitive data and potentially execute unauthorized actions.
- Exploitability
- Exploitation requires knowledge of the victim application name and its ranking activity; creating an attacker-owned workflow application is necessary for full exploitation.
- Blast radius
- If exploited, this vulnerability could lead to significant data breaches and unauthorized execution of workflows under the victim's application context.
- Prioritized remediation
- Restrict access to the question-ranking endpoint or implement proper permission checks on application_id usage.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from the homepage application question-ranking endpoint when the published victim application has ranking activity in the selected date range and the attacker knows or guesses its name, even though direct application detail and debug-open routes deny access. An attacker who can create and publish a workflow application can place the disclosed identifier in an attacker-owned workflow application-node, trigger that workflow, receive output generated by the victim application, and create durable application_chat and application_chat_record rows under the victim application because save and runtime paths do not verify permission to use the referenced application. No fixed version is available as of this review.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-862
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-15958
- MEDIUMCVE-2026-48974PoC
- HIGHCVE-2026-6079
- MEDIUMCVE-2026-61748PoC
- HIGHCVE-2026-63330PoC
- HIGHCVE-2026-7520
- MEDIUMCVE-2026-7753
- HIGHCVE-2026-55739PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.