PT-2026-96261 · Maxkb · Maxkb

CVE-2026-79916

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.10.5-lts
Description Authenticated workspace members can inject control characters into the AWS Bedrock access key id and secret access key fields. These values are processed by the update aws credentials() function and written to /root/.aws/credentials without safe parsing. This allows an attacker to append a new AWS profile containing a credential process, which can be triggered during a subsequent model-validation request, leading to the execution of arbitrary commands as root via botocore.
Recommendations Update to version 2.10.5-lts.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79916
GHSA-2324-7XJR-9QXG

Affected Products

Maxkb