CVE-2026-44847

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns (None, {}), which Django REST Framework interprets as successful authentication. Combined with optional per-trigger token verification and no backend enforcement of token requirements, any unauthenticated attacker who knows a valid trigger ID can invoke webhook triggers to execute their bound tasks. This vulnerability is fixed in 2.9.0.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) MaxKB es un asistente de IA de código abierto para empresas. Antes de la 2.9.0, el endpoint de activación de webhook de MaxKB (/api/trigger/v1/webhook/{trigger_id}) es accesible sin autenticación. La clase WebhookAuth devuelve incondicionalmente (None, {}), lo que Django REST Framework interpreta como autenticación exitosa. Combinado con la verificación de token opcional por activador y la ausencia de aplicación de requisitos de token por parte del backend, cualquier atacante no autenticado que conozca un ID de activador válido puede invocar activadores de webhook para ejecutar sus tareas vinculadas. Esta vulnerabilidad se corrige en la 2.9.0.

26 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 21:16

Updated : 2026-07-24 11:10


NVD link : CVE-2026-44847

Mitre link : CVE-2026-44847

CVE.ORG link : CVE-2026-44847


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function