CVE-2026-39421 | 1Panel-dev MaxKB up to 2.7.x ToolExecutor sandbox.so LD_PRELOAD protection mechanism (GHSA-9c6w-j7w5-3gf7)

SecurityVulns

A vulnerability described as critical has been identified in 1Panel-dev MaxKB up to 2.7.x. This affects an unknown function of the file sandbox.so of the component ToolExecutor. The manipulation of the argument LD_PRELOAD results in protection mechanism failure.

This vulnerability is reported as CVE-2026-39421. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More