MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The endpoint uses application_id from the URL path without validating ownership, allowing attackers to perform operations under other applications’ policies. This vulnerability is fixed in 2.8.1.
CVSS
No CVSS.
References
Configurations
No configuration.
History
26 May 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-26 21:16
Updated : 2026-06-17 10:47
NVD link : CVE-2026-42337
Mitre link : CVE-2026-42337
CVE.ORG link : CVE-2026-42337
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
