External risk intelligence

MaxKB AWS Credential Injection via Control Characters Allows Root Command Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-79916

MaxKB is an enterprise AI assistant web application. These services are commonly deployed as internet-facing web interfaces or APIs to allow organizational users to access AI capabilities. As a web-based platform intended for enterprise utility, it is frequently exposed to network access.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An authenticated user of the MaxKB AI assistant could potentially execute unauthorized commands on the server. This vulnerability arises from how user-supplied AWS credentials are processed, allowing for the injection of malicious commands that could be run with elevated privileges. The primary concern is confirming if this specific AI assistant is in use and if the affected versions are deployed within the organization.

  • AI assistant allows unauthorized command execution.
  • Could lead to server compromise and data breaches.
  • Confirm MaxKB usage and versions; assess exposure.

Attack Path

How an attacker could exploit the issue

An authenticated user within MaxKB could exploit this vulnerability by manipulating fields related to AWS credentials. By injecting specially crafted control characters, an attacker can trick the system into writing a malicious AWS profile to the credentials file. This profile, when later selected, can be used to execute commands as the root user on the system.

  • Authenticated access to MaxKB is required.
  • Injected control characters in AWS credential fields.
  • Risk of root command execution.

Live Threat

Current exploitation, exposure, and threat context

Authenticated users of MaxKB could compromise the underlying server by injecting malicious commands through AWS credential fields. When supported by the advisory, this could allow an attacker to execute arbitrary code as the root user, potentially impacting the confidentiality, integrity, and availability of the system.

  • Server root credentials and data.
  • Injecting control characters into AWS fields.
  • Unauthorized root command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world remediation for this vulnerability likely involves application owners and platform teams responsible for the MaxKB deployment. The first practical step is to inventory all instances of MaxKB, confirm their network reachability and business criticality, identify the accountable owner for each instance, and then prioritize remediation efforts based on assessed risk.

  • Identify accountable application owners.
  • Verify instance reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is MaxKB?

MaxKB is an open-source AI assistant designed for enterprise environments. It provides organizations with a web-based interface to integrate and interact with large language models, helping teams manage AI workflows and knowledge retrieval directly within their internal infrastructure.

How does CVE-2026-79916 allow command execution?

This vulnerability is classified as CWE-78, or OS Command Injection. It occurs because the application fails to sanitize inputs in AWS credential fields. By injecting special control characters, a user can manipulate the system's configuration file to include malicious commands, which the system then inadvertently executes with root privileges.

Can this vulnerability be triggered without authentication?

No. The attack requires an authenticated workspace member to successfully inject the malicious control characters. Simply accessing the public-facing login page of the AI assistant is not enough to trigger the bug; the attacker must be able to interact with the AWS credential update functionality.

Is my MaxKB instance at risk?

According to Halo Surface Signal, MaxKB is often deployed as an internet-facing web application to provide broad organizational access to AI tools. If your instance is reachable via the network and runs a version prior to 2.10.5-lts, it should be considered a priority for review.

What should I do if I run MaxKB?

The most effective way to address this issue is to upgrade your deployment to version 2.10.5-lts or later, which includes the necessary security fixes. Prior to patching, verify which instances are running in your environment and ensure the accountable owners for those systems are aware of the update requirements.

References