CVE-2026-79917
Last modified
CVE-2026-79917 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_user_id or to the application bound to the caller's token. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_user_id or to the application bound to the caller's token. An attacker with any chat token and a known victim chat_id can create an unauthenticated public ChatShareLink exposing the victim's conversation and can create PublicFileAccess state that makes associated files retrievable without credentials, with no available revoke path. No fixed version is available as of this review.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-79917?
How severe is CVE-2026-79917?
How do I fix CVE-2026-79917?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7991Use after free in UI in Google Chrome prior to 148.0.7778.96…8.8
- CVE-2026-79910Acrobat Reader is affected by an out-of-bounds read vulnerab…5.5
- CVE-2026-79911A security vulnerability has been detected in TOTOLINK N600R…10
- CVE-2026-79912A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_…8.3
- CVE-2026-79913Cloudreve is a self-hosted file management and sharing syste…6.5
- CVE-2026-79916MaxKB is an open-source AI assistant for enterprise. Prior t…9.1
- CVE-2026-79918MaxKB is an open-source AI assistant for enterprise. Prior t…6.3
- CVE-2026-79919MaxKB is an open-source AI assistant for enterprise. Prior t…6.3
- CVE-2026-7992Insufficient validation of untrusted input in UI in Google C…8.8
- CVE-2026-79920Ajenti is a Linux & BSD modular server admin panel. Prior to…9.9
- CVE-2026-79921amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0,…8.9
- CVE-2026-7993Insufficient validation of untrusted input in Payments in Go…4.2
Are you affected by CVE-2026-79917?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
