Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS profile containing credential_process, then select that profile during a later model-validation request so botocore executes an attacker-controlled command as root. This vulnerability is fixed in 2.10.5-lts. | |
| Title | MaxKB AWS Bedrock model credential injection leads to remote code execution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T20:34:47.530Z
Reserved: 2026-08-25T14:59:32.746Z
Link: CVE-2026-79916
No data.
Status : Deferred
Published: 2026-09-21T21:17:12.450
Modified: 2026-09-21T21:17:12.580
Link: CVE-2026-79916
No data.
OpenCVE Enrichment
Updated: 2026-09-21T21:30:11Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')