Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39418

29
FAUCET Score

CVE-2026-39418 is a sandbox bypass vulnerability in MaxKB versions 2.7.1 and below that allows authenticated users with tool-editing permissions to reach internal services blocked by the sandbox's network protection. The flaw exploits the socket.sendto() function with the MSG_FASTOPEN flag, which can establish TCP connections directly through the kernel without invoking the hooked connect() function that performs IP validation. This renders MaxKB's LD_PRELOAD-based network filtering ineffective, as glibc bypasses the wrapper functions entirely when making syscalls. The vulnerability carries a HIGH severity rating with a CVSS score of 7.4, reflecting a network-based attack vector with low complexity and no user interaction required. The impact is limited to authenticated users, but the scope is changed, allowing attackers to potentially access confidential information and modify internal systems. The low EPSS score of 0.0003 suggests minimal real-world exploitation activity currently. This vulnerability has not been flagged as part of CISA's Known Exploited Vulnerabilities catalog, and there is no indication of widespread public exploit code availability. However, the issue is marked as active on vulnerability hotlists and warrants prompt patching. MaxKB users should upgrade to version 2.8.0 or later to remediate this bypass and restore sandbox integrity.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.8.0CPE matchmatch criteria
cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 1st percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / 1Panel-dev/MaxKB/commit/4d06362750b15390437f1d2e4d14ec79baef8559
Patch
github.com / 1Panel-dev/MaxKB/releases/tag/v2.8.0
Release Notes
github.com / 1Panel-dev/MaxKB/security/advisories/GHSA-w9g4-q3gm-6q6w
Vendor Advisory