Skip to main content
Vulnerability Database/CVE-2026-79916

CVE-2026-79916: MaxKB AI Assistant RCE Vulnerability

CVE-2026-79916 is a remote code execution flaw in MaxKB open-source AI assistant allowing authenticated users to inject malicious AWS credentials and execute commands as root. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-79916 Overview

MaxKB, an open-source AI assistant for enterprise, contains a command injection vulnerability in its AWS Bedrock integration prior to version 2.10.5-lts. Authenticated workspace members can inject control characters into the access_key_id and secret_access_key fields. The _update_aws_credentials function writes these values to /root/.aws/credentials without safe parsing, allowing attackers to append arbitrary AWS profiles. By adding a profile containing the credential_process directive and selecting it during a later model-validation request, an attacker triggers botocore to execute arbitrary commands as root. The issue is tracked as [CWE-78] OS Command Injection.

Critical Impact

Any authenticated workspace member can achieve root-level remote code execution on the MaxKB host by abusing the AWS Bedrock credential configuration flow.

Affected Products

  • MaxKB versions prior to 2.10.5-lts
  • MaxKB AWS Bedrock model provider integration (apps/models_provider/impl/aws_bedrock_model_provider)
  • Deployments running the MaxKB service as the root user

Discovery Timeline

  • 2026-09-21 - CVE-2026-79916 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-79916

Vulnerability Analysis

The vulnerability lives in the AWS Bedrock model provider code path. The _update_aws_credentials helper accepts user-supplied access_key_id and secret_access_key values from workspace members and writes them directly into /root/.aws/credentials. Because the function does not sanitize newline characters or validate profile syntax, an attacker can embed newline sequences that terminate the intended profile and begin a new one.

The AWS SDK botocore supports a credential_process directive that instructs the SDK to spawn an external process and read credentials from its stdout. When MaxKB later issues a model-validation request against the attacker-controlled profile, botocore executes the supplied command with the privileges of the MaxKB service, which typically runs as root.

Root Cause

The root cause is missing validation of AWS profile names and credential values before writing them to the on-disk credentials file. The code performed no configparser-based parsing, no allowlist of characters, and no rejection of credential_process or similar directives supplied via user input.

Attack Vector

An authenticated workspace member submits credentials containing embedded newlines and a crafted profile definition through the AWS Bedrock configuration UI. After the credentials file is corrupted with the injected profile, the attacker triggers a model-validation request that references the injected profile name. The AWS SDK reads credential_process from the profile and executes the attacker-controlled command as the MaxKB process user.

python
# Security patch introducing safe parsing and validation
# Source: https://github.com/1Panel-dev/MaxKB/commit/a1e413d196004421ab0953ee0baa13d4ca0fe3c4
+import configparser
 import os
 import re
 from typing import Dict, List

The patch imports configparser and re to validate AWS profile names and credential values before they reach /root/.aws/credentials, blocking newline injection and directives such as credential_process.

Detection Methods for CVE-2026-79916

Indicators of Compromise

  • Unexpected profile sections in /root/.aws/credentials on MaxKB hosts, especially profiles containing a credential_process directive.
  • Newline or control characters within stored AWS credential fields in the MaxKB database.
  • Child processes spawned by the MaxKB Python interpreter or botocore that do not correspond to legitimate model validation activity.
  • Outbound network connections from MaxKB hosts to attacker-controlled infrastructure following an AWS Bedrock model validation request.

Detection Strategies

  • Monitor writes to /root/.aws/credentials and alert on modifications that contain the string credential_process.
  • Inspect MaxKB application logs for AWS Bedrock configuration updates followed closely by model-validation requests referencing newly created profile names.
  • Baseline the expected process tree for the MaxKB service and flag any unexpected shell or interpreter invocations.

Monitoring Recommendations

  • Enable file integrity monitoring on /root/.aws/ and other AWS SDK configuration paths.
  • Forward MaxKB audit logs and host process telemetry to a central data lake for correlation across workspace activity and process execution events.
  • Track authenticated workspace member actions that modify model provider credentials and require review of high-privilege configuration changes.

How to Mitigate CVE-2026-79916

Immediate Actions Required

  • Upgrade MaxKB to version 2.10.5-lts or later, which introduces configparser-based validation of AWS profile names and credential values.
  • Rotate any AWS access keys previously configured through the MaxKB Bedrock integration, treating them as potentially exposed.
  • Audit /root/.aws/credentials on every MaxKB host and remove profiles that were not created by an authorized administrator.
  • Review workspace member permissions and revoke access for accounts that should not manage model provider credentials.

Patch Information

The fix is available in MaxKB v2.10.5-lts and was introduced by Pull Request #6418 with commit a1e413d. Additional context is provided in GitHub Security Advisory GHSA-2324-7xjr-9qxg.

Workarounds

  • Run the MaxKB service as a dedicated non-root system account to reduce the impact of arbitrary command execution.
  • Restrict which workspace members can configure model providers until the patched version is deployed.
  • Remove or lock down /root/.aws/credentials so the MaxKB process cannot append arbitrary profiles at runtime.
bash
# Configuration example: restrict AWS credentials file and validate contents
sudo chattr +i /root/.aws/credentials
sudo grep -R "credential_process" /root/.aws/ /home/*/.aws/ 2>/dev/null
sudo systemctl edit maxkb --full   # change User= to a non-root service account

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.