CVE-2026-79916
9.11Panel-dev · MaxKB
MaxKB is vulnerable to OS command injection via improper neutralization of control characters in AWS credential fields, allowing authenticated users to execute arbitrary commands as root.
Executive summary
A critical OS command injection vulnerability in MaxKB allows authenticated workspace members to achieve arbitrary code execution as the root user.
Vulnerability
This vulnerability occurs due to improper neutralization of special elements in the AWS Bedrock credential fields. An authenticated attacker can inject control characters to manipulate the application configuration, ultimately leading to OS command injection when the system executes commands with root privileges.
Business impact
The ability for an authenticated user to achieve root-level code execution poses a catastrophic risk to the integrity and confidentiality of the host environment. Given the CVSS score of 9.1, this flaw allows an attacker to bypass security controls, potentially leading to full system compromise, exfiltration of sensitive AI data, and total loss of service availability.
Remediation
Immediate Action: Upgrade MaxKB to version 2.10.5-lts or later immediately to apply the required fix for credential parsing.
Proactive Monitoring: Review audit logs for suspicious activity involving AWS credential updates or unexpected process execution spawned by the application service.
Compensating Controls: Implement strict network segmentation for the AI assistant and restrict the application service account permissions to the minimum necessary level, preventing the application from running with elevated root privileges where possible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a severe security risk that must be prioritized for remediation. Organizations using MaxKB should verify their current deployment version and apply the 2.10.5-lts update without delay to eliminate the command injection vector. Failure to patch allows any authenticated workspace member to escalate their privileges to root, resulting in total system control.
More 1Panel-dev CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section