CVE-2026-79918 Overview
MaxKB is an open-source AI assistant for enterprise use. Versions prior to 2.10.6-lts contain a sandbox bypass in the ToolExecutor component. The LD_PRELOAD-based sandbox hooks execve, execvpe, and execveat to block subprocess creation but fails to hook fexecve. An authenticated attacker capable of executing tool code can invoke fexecve to start a process outside the sandbox's intended subprocess policy. The issue is fixed in version 2.10.6-lts and is tracked under [CWE-693: Protection Mechanism Failure].
Critical Impact
Authenticated attackers can bypass the ToolExecutor subprocess restriction and execute arbitrary binaries, undermining the sandbox's containment guarantees.
Affected Products
- MaxKB by 1Panel-dev
- MaxKB versions prior to 2.10.6-lts
- Deployments using the LD_PRELOAD ToolExecutor sandbox
Discovery Timeline
- 2026-09-21 - CVE-2026-79918 published to NVD
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-79918
Vulnerability Analysis
MaxKB isolates tool code execution using an LD_PRELOAD shim implemented in installer/sandbox.c. The shim intercepts subprocess-spawning libc functions and calls allow_create_subprocess() before delegating to the real symbol. When the policy denies subprocess creation, the hook returns a permission-denied error.
The original implementation intercepted execve, execvpe, and execveat but omitted fexecve. The fexecve function executes a program referenced by an open file descriptor rather than a path, and on glibc it is implemented independently of the hooked path-based variants. Because the sandbox never resolved or wrapped fexecve, calls to that symbol resolved directly to the libc implementation and bypassed the subprocess check.
An authenticated user with the ability to run tool code inside MaxKB can open a file descriptor to any executable available in the container and invoke fexecve to spawn it. This defeats the sandbox's stated goal of preventing subprocess creation from tool code.
Root Cause
The root cause is an incomplete set of intercepted symbols in the LD_PRELOAD sandbox. The protection mechanism enumerated only a subset of the exec-family functions, leaving fexecve as an unfiltered path to execve-equivalent behavior. This is a classic [CWE-693] protection mechanism failure where the control does not cover all functionally equivalent APIs.
Attack Vector
Exploitation requires an authenticated MaxKB account with permission to submit or execute tool code. The attacker writes tool code that opens a file descriptor with open() on a target binary, then calls fexecve(fd, argv, envp). Because the sandbox does not resolve real_fexecve or gate it through allow_create_subprocess(), the call proceeds to libc and starts the process outside the intended policy.
int __execve(const char *filename, char *const argv[], char *const envp[]) {
return execve(filename, argv, envp);
}
+int fexecve(int fd, char *const argv[], char *const envp[]) {
+ RESOLVE_REAL(fexecve);
+ if (!allow_create_subprocess()) return throw_permission_denied_err(true, "create subprocess");
+ return real_fexecve(fd, argv, envp);
+}
int execveat(int dirfd, const char *pathname,
char *const argv[], char *const envp[], int flags) {
RESOLVE_REAL(execveat);
Source: GitHub commit 6fa7947. The patch adds an fexecve wrapper that resolves the real symbol and enforces the same allow_create_subprocess() check applied to the other exec-family calls.
Detection Methods for CVE-2026-79918
Indicators of Compromise
- Unexpected child processes spawned by the MaxKB ToolExecutor worker where the parent should be sandboxed.
- Tool code containing calls to fexecve or Python bindings such as os.execve wrappers that operate on file descriptors.
- Process telemetry showing binaries executed from /proc/self/fd/<n> paths, which is characteristic of fexecve invocations.
Detection Strategies
- Audit MaxKB tool definitions and stored user tool code for references to fexecve, ctypes.CDLL("libc.so.6"), or dynamic loading of libc symbols.
- Enable Linux process auditing (auditd) rules on the MaxKB host to record execve and execveat syscalls from the ToolExecutor process tree.
- Correlate MaxKB application logs against subprocess events to identify tool executions that produced child processes despite the sandbox being active.
Monitoring Recommendations
- Monitor the MaxKB container for outbound network connections originating from processes other than the expected Python interpreter.
- Track deployed MaxKB versions across the environment and flag any instance running a build older than 2.10.6-lts.
- Review authenticated user activity for anomalous tool creation or modification events preceding subprocess anomalies.
How to Mitigate CVE-2026-79918
Immediate Actions Required
- Upgrade MaxKB to version 2.10.6-lts or later, which adds the missing fexecve hook.
- Restrict tool creation and execution permissions to trusted users until the upgrade is complete.
- Rotate credentials and API keys that were accessible from the MaxKB runtime environment if exploitation is suspected.
Patch Information
The fix is available in MaxKB release v2.10.6-lts and documented in GitHub Security Advisory GHSA-9mh9-v949-fwqh. The patch commit 6fa7947 adds an fexecve interceptor to installer/sandbox.c that enforces the same allow_create_subprocess() gate as the other exec-family hooks.
Workarounds
- Run the MaxKB ToolExecutor inside a container with a restrictive seccomp profile that denies the execve, execveat, and fexecve syscalls at the kernel level.
- Disable or gate authenticated access to the tool code execution feature until the patched version is deployed.
- Apply Linux capability restrictions and read-only root filesystems to reduce the impact of a successful sandbox bypass.
# Upgrade MaxKB to the fixed release
docker pull 1panel/maxkb:v2.10.6-lts
docker stop maxkb && docker rm maxkb
docker run -d --name=maxkb \
--security-opt seccomp=/etc/docker/seccomp-no-exec.json \
--read-only \
-p 8080:8080 \
1panel/maxkb:v2.10.6-lts
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
