Beveiligingsadvies

CVE-2026-56779

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-25 18:11:12
Laatst bijgewerkt 2026-07-28 01:49:46
Toegewezen door VulnCheck
CVSS-score 6.4
Status PUBLISHED

Beschrijving

MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by supplying unvalidated downloadCallbackUrl and download_url parameters. Attackers with default workspace USER role can exploit this to access internal network services by providing malicious URLs to the ToolSerializer endpoints.