Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel maxkb |
|
| Vendors & Products |
1panel
1panel maxkb |
Thu, 25 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by supplying unvalidated downloadCallbackUrl and download_url parameters. Attackers with default workspace USER role can exploit this to access internal network services by providing malicious URLs to the ToolSerializer endpoints. | |
| Title | MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-25T18:11:12.206Z
Reserved: 2026-06-23T01:22:22.572Z
Link: CVE-2026-56779
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T07:15:16Z