CVE-2026-39418 is a sandbox bypass vulnerability in MaxKB versions 2.7.1 and below that allows authenticated users with tool-editing permissions to reach internal services blocked by the sandbox's network protection. The flaw exploits the socket.sendto() function with the MSG_FASTOPEN flag, which can establish TCP connections directly through the kernel without invoking the hooked connect() function that performs IP validation. This renders MaxKB's LD_PRELOAD-based network filtering ineffective, as glibc bypasses the wrapper functions entirely when making syscalls. The vulnerability carries a HIGH severity rating with a CVSS score of 7.4, reflecting a network-based attack vector with low complexity and no user interaction required. The impact is limited to authenticated users, but the scope is changed, allowing attackers to potentially access confidential information and modify internal systems. The low EPSS score of 0.0003 suggests minimal real-world exploitation activity currently. This vulnerability has not been flagged as part of CISA's Known Exploited Vulnerabilities catalog, and there is no indication of widespread public exploit code availability. However, the issue is marked as active on vulnerability hotlists and warrants prompt patching. MaxKB users should upgrade to version 2.8.0 or later to remediate this bypass and restore sandbox integrity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.0CPE matchmatch criteria | cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.